From eb81417e60a662951fe3fc912f0c4f85f0300e97 Mon Sep 17 00:00:00 2001 From: Jeremy Paige Date: Fri, 8 Oct 2021 15:43:42 -0700 Subject: [PATCH] Version 6.2.2.1 --- CHANGES.rst | 8 ++++++++ docs/releasenotes/6.2.2.1.rst | 10 ++++++++++ docs/releasenotes/index.rst | 1 + src/PIL/_version.py | 2 +- 4 files changed, 20 insertions(+), 1 deletion(-) create mode 100644 docs/releasenotes/6.2.2.1.rst diff --git a/CHANGES.rst b/CHANGES.rst index e85716f80..fd8eca6ef 100644 --- a/CHANGES.rst +++ b/CHANGES.rst @@ -2,6 +2,14 @@ Changelog (Pillow) ================== +6.2.2.1 (2021-10-08) +------------------ + +- This is the first Pillow release to support Python 2.7 from ActiveState + +- Catch SGI out-of-bounds reads. CVE 2020-11538 + [ucodery] + 6.2.2 (2020-01-02) ------------------ diff --git a/docs/releasenotes/6.2.2.1.rst b/docs/releasenotes/6.2.2.1.rst new file mode 100644 index 000000000..8912fb798 --- /dev/null +++ b/docs/releasenotes/6.2.2.1.rst @@ -0,0 +1,10 @@ +6.2.2.1 +------- + +Security +======== + +This release addresses CVE-2020-11538. + +CVE-2019-11538 is regarding SGI images. An out-of-bounds read can occur in the +parsing of SGI image files. diff --git a/docs/releasenotes/index.rst b/docs/releasenotes/index.rst index 770b604fa..88ac182ec 100644 --- a/docs/releasenotes/index.rst +++ b/docs/releasenotes/index.rst @@ -6,6 +6,7 @@ Release Notes .. toctree:: :maxdepth: 2 + 6.2.2.1 6.2.2 6.2.1 6.2.0 diff --git a/src/PIL/_version.py b/src/PIL/_version.py index df16dce60..d4fd833ad 100644 --- a/src/PIL/_version.py +++ b/src/PIL/_version.py @@ -1,2 +1,2 @@ # Master version for Pillow -__version__ = "6.2.2" +__version__ = "6.2.2.1"