python-Pillow

Edit Package python-Pillow
No description set
Refresh
Refresh
Source Files
Filename Size Changed
001-Corrected-negative-seeks.patch 0000003619 3.53 KB
002-Added-decompression-bomb-checks.patch 0000002549 2.49 KB
003-Raise-error-if-dimension-is-a-string.patch 0000001523 1.49 KB
004-Catch-buffer-overruns.patch 0000003530 3.45 KB
005-Catch-PCX-P-mode-buffer-overrun.patch 0000001592 1.55 KB
006-Catch-SGI-buffer-overruns.patch 0000003501 3.42 KB
007-Ensure-previous-FLI-frame-is-loaded.patch 0000001417 1.38 KB
008-Catch-FLI-buffer-overrun.patch 0000001874 1.83 KB
009-Invalid-number-of-bands-in-FPX-image.patch 0000001720 1.68 KB
Pillow-5.2.0.tar.gz 0014499068 13.8 MB
python-Pillow.changes 0000061750 60.3 KB
python-Pillow.spec 0000007033 6.87 KB
test_images_01.tar.gz 0000011181 10.9 KB
Revision 2 (latest revision is 10)
Johannes Grassler's avatar Johannes Grassler (jgrassler) accepted request 811228 from Jacek Tomasiak's avatar Jacek Tomasiak (jtomasiak) (revision 2)
- Add 001-Corrected-negative-seeks.patch
   * From upstream, backported
   * Fixes part of CVE-2019-16865, bsc#1153191
- Add 002-Added-decompression-bomb-checks.patch
   * From upstream, backported
   * Fixes part of CVE-2019-16865, bsc#1153191
- Add 003-Raise-error-if-dimension-is-a-string.patch
   * From upstream, backported
   * Fixes part of CVE-2019-16865, bsc#1153191
- Add 004-Catch-buffer-overruns.patch
   * From upstream, backported
   * Fixes part of CVE-2019-16865, bsc#1153191
- Add 005-Catch-PCX-P-mode-buffer-overrun.patch
   * From upstream, backported
   * Fixes CVE-2020-5312, bsc#1160152
- Add 006-Catch-SGI-buffer-overruns.patch
   * From upstream, backported
   * Fixes CVE-2020-5311, bsc#1160151
- Add 007-Ensure-previous-FLI-frame-is-loaded.patch
   * From upstream, backported
   * Fixes https://github.com/python-pillow/Pillow/issues/2649
   * Uncovers CVE-2020-5313, bsc#1160153
- Add 008-Catch-FLI-buffer-overrun.patch
   * From upstream, backported
   * Fixes CVE-2020-5313, bsc#1160153
- Add 009-Invalid-number-of-bands-in-FPX-image.patch
   * From upstream, backported
   * Fixes CVE-2019-19911, bsc#1160192
Comments 0
openSUSE Build Service is sponsored by