From abaa75b10f899ada8dd05b23cc03205064394bc6 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Fri, 22 Jan 2021 20:28:19 +0000 Subject: gentoo resync : 22.01.2021 --- metadata/glsa/glsa-202101-08.xml | 48 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 metadata/glsa/glsa-202101-08.xml (limited to 'metadata/glsa/glsa-202101-08.xml') diff --git a/metadata/glsa/glsa-202101-08.xml b/metadata/glsa/glsa-202101-08.xml new file mode 100644 index 000000000000..64adcec9d255 --- /dev/null +++ b/metadata/glsa/glsa-202101-08.xml @@ -0,0 +1,48 @@ + + + + Pillow: Multiple vulnerabilities + Multiple vulnerabilities have been found in Pillow, the worst of + which could result in a Denial of Service condition. + + pillow + 2021-01-11 + 2021-01-11 + 763210 + remote + + + 8.1.0 + 8.1.0 + + + +

Python Imaging Library (fork)

+
+ +

Multiple vulnerabilities have been discovered in Pillow. Please review + the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Pillow users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-python/pillow-8.1.0" + +
+ + CVE-2020-35653 + CVE-2020-35654 + CVE-2020-35655 + + sam_c + sam_c +
-- cgit v1.2.3