mirror of
				https://github.com/python-pillow/Pillow.git
				synced 2025-11-04 01:47:47 +03:00 
			
		
		
		
	
		
			
				
	
	
		
			21 lines
		
	
	
		
			749 B
		
	
	
	
		
			ReStructuredText
		
	
	
	
	
	
			
		
		
	
	
			21 lines
		
	
	
		
			749 B
		
	
	
	
		
			ReStructuredText
		
	
	
	
	
	
6.2.2
 | 
						|
-----
 | 
						|
 | 
						|
Security
 | 
						|
========
 | 
						|
 | 
						|
This release fixes several buffer overflow issues and a DOS attack vulnerability.
 | 
						|
 | 
						|
:cve:`2020-5310`, :cve:`2020-5311`, :cve:`2020-5312`, :cve:`2020-5313`: Overflow checks added
 | 
						|
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
 | 
						|
 | 
						|
Overflow checks have been added when calculating the size of a memory block to be reallocated
 | 
						|
in the processing of TIFF, SGI, PCX and FLI images.
 | 
						|
 | 
						|
:cve:`2019-19911`: DOS attack vulnerability
 | 
						|
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
 | 
						|
 | 
						|
If an FPX image reports that it has a large number of bands, a large amount of
 | 
						|
resources will be used when trying to process the image. This is fixed by
 | 
						|
limiting the number of bands to those usable by Pillow.
 |