mirror of
				https://github.com/python-pillow/Pillow.git
				synced 2025-10-31 16:07:30 +03:00 
			
		
		
		
	Added release notes for 9.0.1
This commit is contained in:
		
							parent
							
								
									596eaf35cc
								
							
						
					
					
						commit
						8ef2d987ab
					
				
							
								
								
									
										23
									
								
								docs/releasenotes/9.0.1.rst
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										23
									
								
								docs/releasenotes/9.0.1.rst
									
									
									
									
									
										Normal file
									
								
							|  | @ -0,0 +1,23 @@ | |||
| 9.0.1 | ||||
| ----- | ||||
| 
 | ||||
| Security | ||||
| ======== | ||||
| 
 | ||||
| This release addresses several security problems. | ||||
| 
 | ||||
| :cve:`CVE-2022-24303`: If the path to the temporary directory on Linux or macOS | ||||
| contained a space, this would break removal of the temporary image file after | ||||
| ``im.show()`` (and related actions), and potentially remove an unrelated file. This | ||||
| been present since PIL. | ||||
| 
 | ||||
| :cve:`CVE-2022-22817`: While Pillow 9.0 restricted top-level builtins available to | ||||
| :py:meth:`PIL.ImageMath.eval`, it did not prevent builtins available to lambda | ||||
| expressions. These are now also restricted. | ||||
| 
 | ||||
| Other Changes | ||||
| ============= | ||||
| 
 | ||||
| Pillow 9.0 added support for ``xdg-open`` as an image viewer, but there have been | ||||
| reports that the temporary image file was removed too quickly to be loaded into the | ||||
| final application. A delay has been added. | ||||
|  | @ -14,6 +14,7 @@ expected to be backported to earlier versions. | |||
| .. toctree:: | ||||
|   :maxdepth: 2 | ||||
| 
 | ||||
|   9.0.1 | ||||
|   9.0.0 | ||||
|   8.4.0 | ||||
|   8.3.2 | ||||
|  |  | |||
		Loading…
	
		Reference in New Issue
	
	Block a user