From ac348ea3b1807f805c165cd29a54734000f14c3a Mon Sep 17 00:00:00 2001 From: Hugo van Kemenade Date: Thu, 22 Oct 2020 17:09:20 +0300 Subject: [PATCH] Clarify wording [CI skip] Co-authored-by: nulano --- docs/releasenotes/8.0.1.rst | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/releasenotes/8.0.1.rst b/docs/releasenotes/8.0.1.rst index be10d8e47..e50596e5c 100644 --- a/docs/releasenotes/8.0.1.rst +++ b/docs/releasenotes/8.0.1.rst @@ -13,7 +13,9 @@ Update FreeType used in binary wheels to `2.10.4`_ to fix CVE-2020-15999_: If you use option ``FT_CONFIG_OPTION_USE_PNG`` you should upgrade immediately. -Before Pillow 8.0.0 bitmap fonts were disabled with ``FT_LOAD_NO_BITMAP``, but it is not +We strongly recommend updating to Pillow 8.0.1 if you are using Pillow 8.0.0, which improved support for bitmap fonts. + +In Pillow 7.2.0 and earlier bitmap fonts were disabled with ``FT_LOAD_NO_BITMAP``, but it is not clear if this prevents the exploit and we recommend updating to Pillow 8.0.1. Pillow 8.0.0 and earlier are potentially vulnerable releases, including the last release