Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Fedora 38: 2023-1a120657f9 Critical Resource Issue in Python Pillow

fedora
Calendar Grey November 12, 2023
Dist Fedora Esm H88
The latest upgrade to Python Pillow 9.5.0 addresses significant resource management problems that impacted its performance on Fedora systems.
Update to 9.5.0, backport fix for CVE-2023-44271.

Summary

Python image processing library, fork of the Python Imaging Library (PIL)

This library provides extensive file format support, an efficient

internal representation, and powerful image processing capabilities.

There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt),

devel (development) and doc (documentation).

Update Information:

Update to 9.5.0, backport fix for CVE-2023-44271.

Change Log

* Fri Nov 3 2023 Sandro Mani - 9.5.0-1 - Update to 9.5.0 - Backport fix for CVE-2023-44271

References


[ 1 ] Bug #2247821 - CVE-2023-44271 python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2247821

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1a120657f9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-pillow
Product: Fedora 38
Version: 9.5.0
Release: 1.fc38
URL:
Summary: Python image processing library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here