Backport fix for CVE-2022-24303.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-ee15b98ea1 2022-04-05 15:27:15.299672 --------------------------------------------------------------------------------Name : mingw-python-pillow Product : Fedora 34 Version : 8.1.2 Release : 6.fc34 URL : Summary : MinGW Windows Python pillow library Description : MinGW Windows Python pillow library. --------------------------------------------------------------------------------Update Information: Backport fix for CVE-2022-24303. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 28 2022 Sandro Mani - 8.1.2-6 - Backport fix for CVE-2022-24303 --------------------------------------------------------------------------------References: [ 1 ] Bug #2052683 - CVE-2022-24303 mingw-python-pillow: python-pillow: temporary directory with a space character allows removal of unrelated file after im.show() and related actions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2052683 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-ee15b98ea1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.