—
PYSEC-2022-42979
Details
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / pillow
Introduced in:
0 Fixed in: 11918eac0628ec8ac0812670d9838361ead2d6a4 Fix
pip install --upgrade 'pillow>=11918eac0628ec8ac0812670d9838361ead2d6a4' References
- https://bugs.gentoo.org/855683 [WEB]
- https://github.com/python-pillow/Pillow/commit/11918eac0628ec8ac0812670d9838361ead2d6a4 [FIX]
- https://github.com/python-pillow/Pillow/pull/6402 [WEB]
- https://github.com/python-pillow/Pillow/releases/tag/9.2.0 [WEB]
- https://cwe.mitre.org/data/definitions/409.html [WEB]