Advisories ยป MGASA-2015-0039

Updated python-pillow packages fix CVE-2014-9601

Publication date: 27 Jan 2015
Modification date: 27 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9601

Description

Updated python-pillow packages fix security vulnerability:

Pillow before 2.7.0 and 2.6.2 allows remote attackers to cause a denial of
service via a compressed text chunk in a PNG image that has a large size when
it is decompressed (CVE-2014-9601).
                

References

SRPMS

4/core