Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update pillow to 6.2.2 #21156

Merged
merged 1 commit into from Jan 24, 2020
Merged

Update pillow to 6.2.2 #21156

merged 1 commit into from Jan 24, 2020

Conversation

pyup-bot
Copy link
Contributor

This PR updates pillow from 6.2.1 to 6.2.2.

Changelog

6.2.2

------------------

- This is the last Pillow release to support Python 2.7 3642

- Overflow checks for realloc for tiff decoding. CVE TBD
[wiredfool, radarhere]

- Catch SGI buffer overrun. CVE TBD
[radarhere]

- Catch PCX P mode buffer overrun. CVE TBD
[radarhere]

- Catch FLI buffer overrun. CVE TBD
[radarhere]

- Raise an error for an invalid number of bands in FPX image. CVE-2019-19911
[wiredfool, radarhere]
Links

@wpt-pr-bot wpt-pr-bot added infra wptrunner The automated test runner, commonly called through ./wpt run labels Jan 14, 2020
@gsnedders gsnedders force-pushed the pyup-update-pillow-6.2.1-to-6.2.2 branch from f58e93a to b468e6c Compare January 24, 2020 15:54
@Hexcles Hexcles merged commit 1de7af5 into master Jan 24, 2020
@Hexcles Hexcles deleted the pyup-update-pillow-6.2.1-to-6.2.2 branch January 24, 2020 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
infra wptrunner The automated test runner, commonly called through ./wpt run
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants