RHSA-2020:0580: Important: python-pillow security update
The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.Security Fix(es): python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c (CVE-2020-5311) python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c (CVE-2020-5312) python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of service (CVE-2019-16865) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python-pillow-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python3-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python3-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python3-pillow-tk-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
redhat/python-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1.aa - Upgrade
Upgrade
redhat/python-pillow-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1.aa - Upgrade
Upgrade
redhat/python3-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1.aa - Upgrade
Upgrade
redhat/python3-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1.aa - Upgrade
Upgrade
redhat/python3-pillow-tk-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1.aa - Upgrade
Upgrade
python-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
python3-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1 - Upgrade
Upgrade
python3-pillow-tkto a version that resolves this vulnerability.Fixed in 5.1.1-10.el8_1
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0580?
The severity of RHSA-2020:0580 is rated as moderate.
How do I fix RHSA-2020:0580?
You can fix RHSA-2020:0580 by updating the affected python-pillow package to version 5.1.1-10.el8_1 or later.
What packages are affected by RHSA-2020:0580?
RHSA-2020:0580 affects the python-pillow and python3-pillow packages along with their debuginfo and debugsource variants.
What is the vulnerability in RHSA-2020:0580?
The vulnerability in RHSA-2020:0580 is an out-of-bounds write issue in the expandrow function of the libImaging module.
Is there a workaround for RHSA-2020:0580?
There is no specific workaround for RHSA-2020:0580; updating the affected packages is the recommended action.