Security update for python-Pillow
This update for python-Pillow fixes the following issues: - Fixed ImagePath.Path array handling (bsc#1194552, CVE-2022-22815, bsc#1194551, CVE-2022-22816) - Use snprintf instead of sprintf (bsc#1188574, CVE-2021-34552) - Fix Memory DOS in Icns, Ico and Blp Image Plugins. (bsc#1183110, CVE-2021-27921, bsc#1183108, CVE-2021-27922, bsc#1183107, CVE-2021-27923) - Fix OOB read in SgiRleDecode.c (bsc#1183102, CVE-2021-25293) - Use more specific regex chars to prevent ReDoS (bsc#1183101, CVE-2021-25292) - Fix negative size read in TiffDecode.c (bsc#1183105, CVE-2021-25290) - Raise ValueError if color specifier is too long (bsc#1190229, CVE-2021-23437) - Incorrect error code checking in TiffDecode.c (bsc#1183103, CVE-2021-25289) - OOB Write in TiffDecode.c (bsc#1180833, CVE-2020-35654)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Pillow fixes the following issues: - Fixed ImagePath.Path array handling (bsc#1194552, CVE-2022-22815, bsc#1194551, CVE-2022-22816) - Use snprintf instead of sprintf (bsc#1188574, CVE-2021-34552) - Fix Memory DOS in Icns, Ico and Blp Image Plugins. (bsc#1183110, CVE-2021-27921, bsc#1183108, CVE-2021-27922, bsc#1183107, CVE-2021-27923) - Fix OOB read in SgiRleDecode.c (bsc#1183102, CVE-2021-25293) - Use more specific regex chars to prevent ReDoS (bsc#1183101, CVE-2021-25292) - Fix negative size read in TiffDecode.c (bsc#1183105, CVE-2021-25290) - Raise ValueError if color specifier is too long (bsc#1190229, CVE-2021-23437) - Incorrect error code checking in TiffDecode.c (bsc#1183103, CVE-2021-25289) - OOB Write in TiffDecode.c (bsc#1180833, CVE-2020-35654)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1180833
- https://bugzilla.suse.com/1183101
- https://bugzilla.suse.com/1183102
- https://bugzilla.suse.com/1183103
- https://bugzilla.suse.com/1183105
- https://bugzilla.suse.com/1183107
- https://bugzilla.suse.com/1183108
- https://bugzilla.suse.com/1183110
- https://bugzilla.suse.com/1188574
- https://bugzilla.suse.com/1190229
- https://bugzilla.suse.com/1194551
- https://bugzilla.suse.com/1194552
- https://www.suse.com/security/cve/CVE-2020-35654
- https://www.suse.com/security/cve/CVE-2021-23437
- https://www.suse.com/security/cve/CVE-2021-25289
- https://www.suse.com/security/cve/CVE-2021-25290
- https://www.suse.com/security/cve/CVE-2021-25292
- https://www.suse.com/security/cve/CVE-2021-25293
- https://www.suse.com/security/cve/CVE-2021-27921
- https://www.suse.com/security/cve/CVE-2021-27922
- https://www.suse.com/security/cve/CVE-2021-27923
- https://www.suse.com/security/cve/CVE-2021-34552
- https://www.suse.com/security/cve/CVE-2022-22815
- https://www.suse.com/security/cve/CVE-2022-22816
- https://www.suse.com/support/update/announcement/2024/suse-su-20241673-1/