Eric Soroos 
							
						 
					 
					
						
						
						
						
							
						
						
							87934e22d0 
							
						 
					 
					
						
						
							
							Fix for crash-0da0  
						
						
						
					 
					
						2021-03-31 23:24:30 +02:00 
						 
				 
			
				
					
						
							
							
								Eric Soroos 
							
						 
					 
					
						
						
						
						
							
						
						
							53c80281d7 
							
						 
					 
					
						
						
							
							fix for crash-8115  
						
						
						
					 
					
						2021-03-31 22:23:57 +02:00 
						 
				 
			
				
					
						
							
							
								Eric Soroos 
							
						 
					 
					
						
						
						
						
							
						
						
							45530d5ce1 
							
						 
					 
					
						
						
							
							fixes crash-74d2  
						
						
						
					 
					
						2021-03-31 22:23:57 +02:00 
						 
				 
			
				
					
						
							
							
								Eric Soroos 
							
						 
					 
					
						
						
						
						
							
						
						
							cbdce6c5d0 
							
						 
					 
					
						
						
							
							Fix for CVE-2021-25291  
						
						... 
						
						
						
						* Invalid tile boundaries lead to OOB Read in TiffDecode.c, in TiffReadRGBATile
* Check the tile validity before attempting to read. 
						
					 
					
						2021-03-01 19:04:48 +11:00 
						 
				 
			
				
					
						
							
							
								Eric Soroos 
							
						 
					 
					
						
						
						
						
							
						
						
							86f02f7c70 
							
						 
					 
					
						
						
							
							Fix negative size read in TiffDecode.c  
						
						... 
						
						
						
						* Caught by oss-fuzz runs
* CVE-2021-25290 
						
					 
					
						2021-03-01 19:04:42 +11:00 
						 
				 
			
				
					
						
							
							
								Eric Soroos 
							
						 
					 
					
						
						
						
						
							
						
						
							3fee28eb94 
							
						 
					 
					
						
						
							
							Incorrect error code checking in TiffDecode.c  
						
						... 
						
						
						
						* since Pillow 8.1.0
* CVE-2021-25289 
						
					 
					
						2021-03-01 18:51:13 +11:00 
						 
				 
			
				
					
						
							
							
								wiredfool 
							
						 
					 
					
						
						
						
						
							
						
						
							eb8c1206d6 
							
						 
					 
					
						
						
							
							Fix CVE-2020-35654 - OOB Write in TiffDecode.c  
						
						... 
						
						
						
						* In some circumstances with some versions of libtiff (4.1.0+), there
  could be a 4 byte out of bound write when decoding a YCbCr tiff.
* The Pillow code dates to 6.0.0
* Found and reported through Tidelift 
						
					 
					
						2021-01-02 20:37:48 +11:00 
						 
				 
			
				
					
						
							
							
								Andrew Murray 
							
						 
					 
					
						
						
						
						
							
						
						
							26bf1c3524 
							
						 
					 
					
						
						
							
							Moved CVE images to pillow-depends  
						
						
						
					 
					
						2020-09-23 00:14:40 +10:00