Advisories ยป MGASA-2023-0164

Updated python-pillow packages fix security vulnerability

Publication date: 16 May 2023
Modification date: 16 May 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-30595 , CVE-2022-45198

Description

libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in
the processing of invalid TGA image files. (CVE-2022-30595)
Improper Handling of Highly Compressed GIF Data (Data Amplification).
(CVE-2022-45198)
                

References

SRPMS

8/core