Debian 10222 Published by

A pillow security update has been released for Debian GNU/Linux 8 Extended LTS to address multiple out-of-bounds issues.



ELA-259-1 pillow security update

Package pillow
Version 2.6.1-2+deb8u5
Related CVEs CVE-2020-10177
It was noticed that in Pillow before 7.1.0, there are multiple out-of-bounds reads in libImaging/FliDecode.c.

For Debian 8 jessie, these problems have been fixed in version 2.6.1-2+deb8u5.

We recommend that you upgrade your pillow packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-259-1 pillow security update