Fedora Linux 8567 Published by

A python2-pillow security update has been released for Fedora 32.



SECURITY: Fedora 32 Update: python2-pillow-6.2.2-5.fc32


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-0ece308612
2021-03-15 01:05:35.340646
--------------------------------------------------------------------------------

Name : python2-pillow
Product : Fedora 32
Version : 6.2.2
Release : 5.fc32
URL :   http://python-pillow.github.io/
Summary : Python image processing library
Description :
Python image processing library, fork of the Python Imaging Library (PIL)

This library provides extensive file format support, an efficient
internal representation, and powerful image processing capabilities.

This is a minimal compatibility package for   https://pagure.io/fesco/issue/2266

--------------------------------------------------------------------------------
Update Information:

This update fixes CVE-2021-27921, CVE-2021-27922 and CVE-2021-27923. ----
Backport fixes for CVE-2021-25289, CVE-2021-25290, CVE-2021-25291,
CVE-2021-25292, CVE-2021-25293
--------------------------------------------------------------------------------
ChangeLog:

* Sat Mar 6 2021 Sandro Mani - 6.2.2-5
- Backport patch for CVE-2021-2792{1,2,3}
* Fri Mar 5 2021 Sandro Mani - 6.2.2-4
- Backport fixes for CVE-2020-35653, CVE-2020-35654, CVE-2020-35655
- Backport fixes for CVE-2021-25289, CVE-2021-25290, CVE-2021-25291, CVE-2021-25292, CVE-2021-25293
* Wed Jul 29 2020 Fedora Release Engineering - 6.2.2-3
- Rebuilt for   https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1933899 - python-pillow-8.1.1 is available
  https://bugzilla.redhat.com/show_bug.cgi?id=1933899
[ 2 ] Bug #1934681 - CVE-2021-25289 python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934681
[ 3 ] Bug #1934682 - CVE-2021-25289 python2-pillow: python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934682
[ 4 ] Bug #1934683 - CVE-2021-25289 mingw-python-pillow: python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934683
[ 5 ] Bug #1934686 - CVE-2021-25290 python-pillow: negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934686
[ 6 ] Bug #1934687 - CVE-2021-25290 python2-pillow: python-pillow: negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934687
[ 7 ] Bug #1934688 - CVE-2021-25290 mingw-python-pillow: python-pillow: negative-offset memcpy with an invalid size in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934688
[ 8 ] Bug #1934693 - CVE-2021-25291 python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934693
[ 9 ] Bug #1934694 - CVE-2021-25291 python2-pillow: python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934694
[ 10 ] Bug #1934695 - CVE-2021-25291 mingw-python-pillow: python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934695
[ 11 ] Bug #1934700 - CVE-2021-25292 python-pillow: backtracking regex in PDF parser could be used as a DOS attack [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934700
[ 12 ] Bug #1934701 - CVE-2021-25292 python2-pillow: python-pillow: backtracking regex in PDF parser could be used as a DOS attack [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934701
[ 13 ] Bug #1934702 - CVE-2021-25292 mingw-python-pillow: python-pillow: backtracking regex in PDF parser could be used as a DOS attack [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934702
[ 14 ] Bug #1934706 - CVE-2021-25293 python-pillow: out-of-bounds read in SGIRleDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934706
[ 15 ] Bug #1934707 - CVE-2021-25293 python2-pillow: python-pillow: out-of-bounds read in SGIRleDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934707
[ 16 ] Bug #1934708 - CVE-2021-25293 mingw-python-pillow: python-pillow: out-of-bounds read in SGIRleDecode.c [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1934708
[ 17 ] Bug #1935385 - CVE-2021-27921 python-pillow: reported size of a contained image is not properly checked for a BLP container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935385
[ 18 ] Bug #1935386 - CVE-2021-27921 python2-pillow: python-pillow: reported size of a contained image is not properly checked for a BLP container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935386
[ 19 ] Bug #1935388 - CVE-2021-27921 mingw-python-pillow: python-pillow: reported size of a contained image is not properly checked for a BLP container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935388
[ 20 ] Bug #1935397 - CVE-2021-27922 python-pillow: reported size of a contained image is not properly checked for an ICNS container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935397
[ 21 ] Bug #1935398 - CVE-2021-27922 python2-pillow: python-pillow: reported size of a contained image is not properly checked for an ICNS container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935398
[ 22 ] Bug #1935399 - CVE-2021-27922 mingw-python-pillow: python-pillow: reported size of a contained image is not properly checked for an ICNS container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935399
[ 23 ] Bug #1935402 - CVE-2021-27923 python-pillow: reported size of a contained image is not properly checked for an ICO container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935402
[ 24 ] Bug #1935403 - CVE-2021-27923 python2-pillow: python-pillow: reported size of a contained image is not properly checked for an ICO container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935403
[ 25 ] Bug #1935405 - CVE-2021-27923 mingw-python-pillow: python-pillow: reported size of a contained image is not properly checked for an ICO container [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1935405
[ 26 ] Bug #1936047 - python-pillow-8.1.2 is available
  https://bugzilla.redhat.com/show_bug.cgi?id=1936047
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-0ece308612' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys