From d254e581a1f97c52b3796ddb48d09b48bd16d446 Mon Sep 17 00:00:00 2001 From: Andrew Murray Date: Thu, 1 Jul 2021 13:31:57 +1000 Subject: [PATCH] Added release notes for #5567 --- docs/releasenotes/8.3.0.rst | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/releasenotes/8.3.0.rst b/docs/releasenotes/8.3.0.rst index 0929d75b209..eb4883debff 100644 --- a/docs/releasenotes/8.3.0.rst +++ b/docs/releasenotes/8.3.0.rst @@ -82,6 +82,13 @@ format, through the new ``bitmap_format`` argument:: Security ======== +Buffer overflow +^^^^^^^^^^^^^^^ + +This release addresses :cve:`CVE-2021-34552`. PIL since 1.1.4 and Pillow since 1.0 +allowed parameters passed into a convert function to trigger buffer overflow in +Convert.c. + Parsing XML ^^^^^^^^^^^