Bug 28137 - python-pillow new security issue CVE-2020-3565[3-5]
Summary: python-pillow new security issue CVE-2020-3565[3-5]
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL: https://nvd.nist.gov/vuln/detail/CVE-...
Whiteboard:
Keywords:
Depends on: 29002
Blocks:
  Show dependency treegraph
 
Reported: 2021-01-17 11:38 CET by Zombie Ryushu
Modified: 2021-07-01 18:29 CEST (History)
2 users (show)

See Also:
Source RPM: python-pillow-8.0.1-1.mga8.src.rpm
CVE: CVE-2020-35655
Status comment: Fixed upstream in 8.1.0


Attachments

Description Zombie Ryushu 2021-01-17 11:38:37 CET
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
Zombie Ryushu 2021-01-17 11:38:55 CET

CVE: (none) => CVE-2020-35655

Comment 1 David Walser 2021-01-17 17:36:14 CET
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35655
https://ubuntu.com/security/CVE-2020-35655
https://bugzilla.redhat.com/show_bug.cgi?id=1915432

Whiteboard: (none) => MGA7TOO
Summary: python-pillow security issue CVE-2020-35655 => python-pillow new security issue CVE-2020-35655
Status comment: (none) => Fixed upstream in 8.1.0

Comment 2 Nicolas Lécureuil 2021-01-17 19:59:25 CET
Freeze push asked for cauldron

CC: (none) => mageia

Comment 3 Lewis Smith 2021-01-17 21:32:12 CET
Checked not a duplicate.
Various maintainers for this SRPM, so assigning it globally.

Assignee: bugsquad => pkg-bugs

Comment 4 David Walser 2021-01-18 08:02:18 CET
python-pillow-8.1.0-1.mga8 uploaded for Cauldron.

Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)

Comment 5 David Walser 2021-01-20 15:34:10 CET
Ubuntu has issued an advisory for this on January 18:
https://ubuntu.com/security/notices/USN-4697-1

Summary: python-pillow new security issue CVE-2020-35655 => python-pillow new security issue CVE-2020-3565[3-5]
Severity: normal => major

Comment 6 David Walser 2021-01-21 16:58:21 CET
Fedora has issued an advisory for this today (January 21):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4VRCCSORJBMRUY5NGYWMCKVE5VO5JOO5/

CC: (none) => luigiwalser

David Walser 2021-05-29 00:36:57 CEST

Depends on: (none) => 29002

Comment 7 David Walser 2021-07-01 18:29:22 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.