mirror of
https://github.com/python-pillow/Pillow.git
synced 2025-10-24 12:41:11 +03:00
21 lines
749 B
ReStructuredText
21 lines
749 B
ReStructuredText
6.2.2
|
|
-----
|
|
|
|
Security
|
|
========
|
|
|
|
This release fixes several buffer overflow issues and a DOS attack vulnerability.
|
|
|
|
:cve:`2020-5310`, :cve:`2020-5311`, :cve:`2020-5312`, :cve:`2020-5313`: Overflow checks added
|
|
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
|
|
|
Overflow checks have been added when calculating the size of a memory block to be reallocated
|
|
in the processing of TIFF, SGI, PCX and FLI images.
|
|
|
|
:cve:`2019-19911`: DOS attack vulnerability
|
|
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
|
|
|
If an FPX image reports that it has a large number of bands, a large amount of
|
|
resources will be used when trying to process the image. This is fixed by
|
|
limiting the number of bands to those usable by Pillow.
|