Published
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
18 packages
- python312Packages.pillow-heif
- python312Packages.pillow-jpls
- python312Packages.pillowfight
- python313Packages.pillow-heif
- python313Packages.pillow-jpls
- python313Packages.pillowfight
- python314Packages.pillow-heif
- python314Packages.pillow-jpls
- python314Packages.pillowfight
- python312Packages.types-pillow
- python313Packages.types-pillow
- python314Packages.types-pillow
- python312Packages.pypillowfight
- python313Packages.pypillowfight
- python314Packages.pillow
- python313Packages.pillow-avif-plugin
- python312Packages.pillow-avif-plugin
- python314Packages.pypillowfight
- @LeSuisse added package python314Packages.pillow
- @LeSuisse removed maintainer @mweinelt
- @LeSuisse accepted
- @LeSuisse published on GitHub
Pillow has an out-of-bounds write when loading PSD images
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
References
-
https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc x_refsource_CONFIRM
-
https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc x_refsource_CONFIRM
Affected products
Pillow
- ==>= 10.3.0, < 12.1.1
Matching in nixpkgs
pkgs.python312Packages.pillow
Friendly PIL fork (Python Imaging Library)
pkgs.python313Packages.pillow
Friendly PIL fork (Python Imaging Library)
pkgs.python314Packages.pillow
Friendly PIL fork (Python Imaging Library)
Package maintainers
Ignored maintainers (1)
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>