MGASA-2015-0039

Source
https://advisories.mageia.org/MGASA-2015-0039.html
Import Source
https://advisories.mageia.org/MGASA-2015-0039.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2015-0039
Related
Published
2015-01-27T21:08:29Z
Modified
2015-01-27T20:59:07Z
Summary
Updated python-pillow packages fix CVE-2014-9601
Details

Updated python-pillow packages fix security vulnerability:

Pillow before 2.7.0 and 2.6.2 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed (CVE-2014-9601).

References
Credits

Affected packages

Mageia:4 / python-pillow

Package

Name
python-pillow
Purl
pkg:rpm/mageia/python-pillow?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.2-1.1.mga4

Ecosystem specific

{
    "section": "core"
}