[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-3090-2 -- pillow regresssion

ID: oval:org.secpod.oval:def:703290Date: (C)2016-10-03   (M)2023-12-26
Class: PATCHFamily: unix




pillow: Python Imaging Library compatibility layer Details: USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601 caused a regression which resulted in failures when processing certain png images. This update temporarily reverts the security fix for CVE-2014-9601 pending further investigation. We apologize for the inconvenience. Original advisory Pillow could be made to crash if it received specially crafted input or opened a specially crafted file.

Platform:
Ubuntu 14.04
Product:
python-imaging
python-pil
python3-imaging
python3-pil
Reference:
USN-3090-2
CVE-2016-2533
CVE-2016-0775
CVE-2016-0740
CVE-2014-9601
CVE-2014-3589
CVE    5
CVE-2016-0740
CVE-2016-2533
CVE-2014-3589
CVE-2014-9601
...
CPE    5
cpe:/a:python_imaging_project:python3-imaging
cpe:/o:ubuntu:ubuntu_linux:14.04
cpe:/a:python:python-pil
cpe:/a:pythonware:python_imaging
...

© SecPod Technologies