Movatterモバイル変換


[0]ホーム

URL:


ContentsMenuExpandLight modeDark modeAuto light/dark, in light modeAuto light/dark, in dark modeSkip to content
Pillow (PIL Fork) 12.0.0 documentation
Light LogoDark Logo
Pillow (PIL Fork) 12.0.0 documentation
Back to top

8.1.1 (2021-03-01)

Security

CVE 2021-25289: Correct the fix forCVE 2020-35654

The previous fix forCVE 2020-35654 was insufficient due to incorrecterror checking inTiffDecode.c.

CVE 2021-25290: Fix buffer overflow inTiffDecode.c

InTiffDecode.c, there is a negative-offsetmemcpy with an invalid size.

CVE 2021-25291: Fix buffer overflow inTIFFReadRGBATile

InTiffDecode.c, invalid tile boundaries could lead to an out-of-boundsread inTIFFReadRGBATile.

CVE 2021-25292: Fix DOS attack

The PDF parser has a catastrophic backtracking regex that could be used as aDOS attack.

CVE 2021-25293: Fix buffer overflow inSgiRleDecode.c

There is an out-of-bounds read inSgiRleDecode.c since Pillow 4.3.0.

Other changes

A crash with the feature flags for libimagequant, libjpeg-turbo, WebP and XCB onunreleased Python 3.10 has been fixed (#5193).

On this page

[8]ページ先頭

©2009-2025 Movatter.jp