Commit Graph

13944 Commits

Author SHA1 Message Date
nulano
74c60b47a8
simplify patch, also check zipfile 2022-10-30 23:45:49 +00:00
TrellixVulnTeam
e50a3a213e
Adding tarfile member sanitization to extractall() 2022-10-30 23:44:48 +00:00
Hugo van Kemenade
4fc0a4ceb2 9.4.0.dev0 version bump 2022-10-29 17:22:07 +03:00
Hugo van Kemenade
d594f4cb8d Update CHANGES.rst [ci skip] 2022-10-29 15:25:53 +03:00
Hugo van Kemenade
909dc64ed5 9.3.0 version bump 2022-10-29 15:21:20 +03:00
Hugo van Kemenade
1a51ce7b95
Merge pull request #6699 from hugovk/security-libtiff_buffer 2022-10-29 15:06:57 +03:00
Hugo van Kemenade
2444cddab2
Merge pull request #6700 from hugovk/security-samples_per_pixel-sec 2022-10-29 13:16:49 +03:00
Andrew Murray
744f455830 Added release notes 2022-10-29 12:08:59 +03:00
Hugo van Kemenade
0846bfae48 Add to release notes 2022-10-29 12:06:33 +03:00
Hugo van Kemenade
799a6a0105 Fix linting 2022-10-29 12:06:30 +03:00
Hugo van Kemenade
00b25fd3ac Hide UserWarning in logs
Tests/test_file_tiff.py::TestFileTiff::test_oom[Tests/images/oom-225817ca0f8c663be7ab4b9e717b02c661e66834.tif]
  PIL/TiffImagePlugin.py:850: UserWarning: Corrupt EXIF data.  Expecting to read 12 bytes but only got 6. 
    warnings.warn(str(msg))

Co-authored-by: Andrew Murray <3112309+radarhere@users.noreply.github.com>
2022-10-29 12:06:27 +03:00
Eric Soroos
05b175ef88 Tighter test case 2022-10-29 12:06:24 +03:00
Eric Soroos
13f2c5ae14 Prevent DOS with large SAMPLESPERPIXEL in Tiff IFD
A large value in the SAMPLESPERPIXEL tag could lead to a memory and
runtime DOS in TiffImagePlugin.py when setting up the context for
image decoding.
2022-10-29 12:06:18 +03:00
Andrew Murray
fa71b11073 Revert "Temporarily skip valgrind failure"
This reverts commit a3e61c1f89.
2022-10-29 12:02:07 +03:00
Andrew Murray
93e5fd4b40 Initialize libtiff buffer 2022-10-29 12:02:03 +03:00
Andrew Murray
e055ef0356
Update CHANGES.rst [ci skip] 2022-10-29 19:22:28 +11:00
Hugo van Kemenade
327db9a545
Merge pull request #6329 from nulano/imagetk-leak
Inline fname2char to fix memory leak
2022-10-29 10:59:54 +03:00
Hugo van Kemenade
966e98f36a
Merge pull request #6330 from nulano/imagingft-leak
Fix memory leaks related to text features
2022-10-29 10:58:36 +03:00
Hugo van Kemenade
e849e93480
Merge pull request #6695 from hugovk/fix-setuptools
Double quotes for old CPython on Windows
2022-10-29 10:53:42 +03:00
Hugo van Kemenade
b656d85dec
Merge pull request #6697 from nulano/gha-windows-set-output
GHA: replace deprecated set-output command with GITHUB_OUTPUT file
2022-10-29 06:47:47 +03:00
Andrew Murray
c3326da8a3
Update CHANGES.rst [ci skip] 2022-10-29 11:31:20 +11:00
Andrew Murray
a048d163d6
Merge pull request #6693 from cgohlke/patch-3
Remove backup implementation of Round for Windows platforms
2022-10-29 11:28:34 +11:00
Andrew Murray
dc0e4dde4f
Merge pull request #6696 from hugovk/update-release-notes
Update release notes for 9.3.0
2022-10-29 11:19:11 +11:00
nulano
7ad021efb0
GHA: use GITHUB_OUTPUT instead of deprecated set-output 2022-10-28 23:16:43 +01:00
Hugo van Kemenade
7adda3d4ab
Merge pull request #6532 from nulano/upload-fribidi 2022-10-28 22:56:13 +03:00
Hugo van Kemenade
88ba3a0cb0 Document 3.11 wheels in 9.3.0 release notes 2022-10-28 22:54:08 +03:00
Andrew Murray
b8fc7340d9
Merge branch 'main' into upload-fribidi 2022-10-28 21:27:56 +11:00
Andrew Murray
b4bf2885f3 Update CHANGES.rst [ci skip] 2022-10-28 21:23:25 +11:00
Hugo van Kemenade
31f66ea963
Merge pull request #6445 from radarhere/set_variation_by_name 2022-10-28 13:21:30 +03:00
Hugo van Kemenade
3ffd2b2b8f Double quotes for old CPython on Windows 2022-10-28 13:02:19 +03:00
Christoph Gohlke
4ab80f663e
Remove backup implementation of Round for Windows platforms 2022-10-27 08:15:36 -07:00
Andrew Murray
fb0e7cdd91 Update CHANGES.rst [ci skip] 2022-10-27 22:33:20 +11:00
Hugo van Kemenade
d0ad0a0d3d
Merge pull request #6562 from nulano/winbuild-update 2022-10-27 14:10:16 +03:00
Hugo van Kemenade
3cd8eaeddb
Merge pull request #6690 from cgohlke/patch-1 2022-10-27 14:09:58 +03:00
Hugo van Kemenade
10aa3bdc6a
Merge pull request #6691 from cgohlke/patch-2 2022-10-27 14:09:05 +03:00
Andrew Murray
d3b471b2ae Update CHANGES.rst [ci skip] 2022-10-27 07:42:18 +11:00
Hugo van Kemenade
454b586f15 Update release notes for 9.3.0 2022-10-26 22:02:13 +03:00
Christoph Gohlke
d97db54be0
Only use ASCII characters in C source file 2022-10-26 11:17:28 -07:00
Christoph Gohlke
6788e8f957
Fix malloc in _imagingft.c:font_setvaraxes 2022-10-26 11:11:30 -07:00
Hugo van Kemenade
8ed46cd568
Merge pull request #6686 from hugovk/test-3.11-final 2022-10-26 14:26:40 +03:00
Hugo van Kemenade
9bbf56b368
Merge pull request #6418 from hmaarrfk/parallel_matrix_convert 2022-10-25 21:11:22 +03:00
Hugo van Kemenade
68b435ed86 Test Python 3.11.0 final 2022-10-25 15:34:31 +03:00
Hugo van Kemenade
7a06bc6357
Merge pull request #6533 from nulano/document_imagedraw_attributes 2022-10-25 13:06:17 +03:00
Hugo van Kemenade
f8b7464d7b
Merge pull request #6685 from radarhere/releasenotes
Added release notes for #6630
2022-10-25 07:07:56 +03:00
Andrew Murray
1324c55ddc Added release notes for #6630 2022-10-25 10:16:47 +11:00
Andrew Murray
d72779ac03 Update CHANGES.rst [ci skip] 2022-10-25 09:03:15 +11:00
Hugo van Kemenade
5a6293bcaf
Merge pull request #6630 from radarhere/exiftags_enum 2022-10-24 23:50:09 +03:00
Hugo van Kemenade
b6e0b668b9
Merge pull request #6682 from radarhere/releasenotes 2022-10-24 15:24:15 +03:00
Hugo van Kemenade
a77eb671a1
Merge pull request #6683 from radarhere/apng 2022-10-24 15:23:45 +03:00
Andrew Murray
46b0644c4f Do not modify previous frame when calculating delta 2022-10-24 22:19:22 +11:00