Added release notes for #7235

This commit is contained in:
Andrew Murray 2023-06-29 20:58:43 +10:00
parent 2de1bf221a
commit ae43cda4c5

View File

@ -157,10 +157,15 @@ TODO
Security
========
TODO
^^^^
Limit size even if one dimension is zero
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
TODO
When performing decompression bomb checks, Pillow did not reject images with
excessive width and zero height, or zero width and excessive height. That has
now been fixed.
This effectively dates to the PIL fork, since problem images would still have
been processed before Pillow started checking for decompression bombs.
Other Changes
=============