Revisions of python-Pillow
Gayane Osipyan (gosipyan)
accepted
request 899424
from
Jacek Tomasiak (jtomasiak)
(revision 7)
- Add 017-CVE-2020-35653.patch * From upstream, backported * Fixes CVE-2020-35653, bsc#1180834 - Add 018-CVE-2021-25287+8.patch * From upstream, backported * Fixes CVE-2021-25287, CVE-2021-25288, bsc#1185805, bsc#1185803 - Add 019-CVE-2021-28675.patch * From upstream, backported * Fixes CVE-2021-28675, bsc#1185804 - Add 020-CVE-2021-28677.patch * From upstream, backported * Fixes CVE-2021-28677, bsc#1185785 - Add 021-CVE-2021-28676.patch * From upstream, backported * Fixes CVE-2021-28676, bsc#1185786 - Add 014-Tests-for-tiff-crashes.patch * From upstream, reimplemented with old test framework * Base change for later CVE test cases + on_ci() helper - Add 015-Fix-negative-size-read-in-TiffDecode.patch * From upstream, backported * CVE-2021-25290, bsc#1183105 - Add 016-Fix-Memory-DOS-in-BLP-ICNS-and-ICO-Image-Plugins.patch * From upstream, backported * CVE-2021-27922, CVE-2021-27923, bsc#1183108, bsc#1183107
Johannes Grassler (jgrassler)
accepted
request 818410
from
Jacek Tomasiak (jtomasiak)
(revision 6)
- Add 011-Fix-OOB-reads-in-FLI-decoding.patch * From upstream, backported * Fixes CVE-2020-10177, bsc#1173413 - Add 012-Fix-bounds-overflow-in-JPEG-2000-decoding.patch * From upstream, backported * Fixes CVE-2020-10994, bsc#1173418 - Add 013-Fix-bounds-overflow-in-PCX-decoding.patch * From upstream, backported * Fixes CVE-2020-10378, bsc#1173416
Johannes Grassler (jgrassler)
accepted
request 816081
from
Jacek Tomasiak (jtomasiak)
(revision 5)
- Remove decompression_bomb.gif and relevant test case to avoid ClamAV scan alerts during build
Dirk Mueller (dirkmueller)
accepted
request 812579
from
Jacek Tomasiak (jtomasiak)
(revision 4)
- Add 001-Corrected-negative-seeks.patch * From upstream, backported * Fixes part of CVE-2019-16865, bsc#1153191 - Add 002-Added-DecompressionBombError.patch * From upstream, backported * Adds DecompressionBombError class * Used by 003-Added-decompression-bomb-checks.patch - Add 003-Added-decompression-bomb-checks.patch * From upstream, backported * Fixes part of CVE-2019-16865, bsc#1153191 - Add 004-Raise-error-if-dimension-is-a-string.patch * From upstream, backported * Fixes part of CVE-2019-16865, bsc#1153191 - Add 005-Catch-buffer-overruns.patch * From upstream, backported * Fixes part of CVE-2019-16865, bsc#1153191 - Add 006-Catch-PCX-P-mode-buffer-overrun.patch * From upstream, backported * Fixes CVE-2020-5312, bsc#1160152 - Add 007-Test-animated-FLI-file.patch * From upstream, backported * Adds test animated FLI file * Used by 008-Ensure-previous-FLI-frame-is-loaded.patch - Add 008-Ensure-previous-FLI-frame-is-loaded.patch * From upstream, backported * Fixes https://github.com/python-pillow/Pillow/issues/2649 * Uncovers CVE-2020-5313, bsc#1160153 - Add 009-Catch-FLI-buffer-overrun.patch * From upstream, backported * Fixes CVE-2020-5313, bsc#1160153 - Add 010-Invalid-number-of-bands-in-FPX-image.patch * From upstream, backported * Fixes CVE-2019-19911, bsc#1160192
Thomas Bechtold (tbechtold)
committed
(revision 3)
osc copypac from project:devel:languages:python package:python-Pillow revision:64, using expand
Thomas Bechtold (tbechtold)
committed
(revision 2)
osc copypac from project:Cloud:OpenStack:Master package:python-Pillow revision:5, using expand
Thomas Bechtold (tbechtold)
committed
(revision 1)
osc copypac from project:Cloud:OpenStack:Master package:python-Pillow revision:5, using expand
Displaying all 7 revisions