RHSA-2020:3185: Important: python-pillow security update
The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.Security Fix(es): python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2 (CVE-2020-11538) python-pillow: out-of-bounds read in ImagingFliDecode when loading FLI images (CVE-2020-5313) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2 - Upgrade
Upgrade
redhat/python-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2 - Upgrade
Upgrade
redhat/python-pillow-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2 - Upgrade
Upgrade
redhat/python3-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2 - Upgrade
Upgrade
redhat/python3-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2 - Upgrade
Upgrade
redhat/python3-pillow-tk-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2 - Upgrade
Upgrade
redhat/python-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2.aa - Upgrade
Upgrade
redhat/python-pillow-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2.aa - Upgrade
Upgrade
redhat/python3-pillowto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2.aa - Upgrade
Upgrade
redhat/python3-pillow-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2.aa - Upgrade
Upgrade
redhat/python3-pillow-tk-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-12.el8_2.aa - Upgrade
Upgrade
python-pillowto a version that resolves this vulnerability.Patch CVE-2020-5313 - Upgrade
Upgrade
python-pillowto a version that resolves this vulnerability.Patch CVE-2020-11538
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3185?
The severity of RHSA-2020:3185 is categorized as critical due to out-of-bounds reads and writes in the python-pillow package.
How do I fix RHSA-2020:3185?
To fix RHSA-2020:3185, you should update the python-pillow package to version 5.1.1-12.el8_2 or later.
Which packages are affected by RHSA-2020:3185?
The affected packages include python-pillow, python3-pillow, and their respective debuginfo and debugsource variants.
What vulnerabilities are addressed in RHSA-2020:3185?
RHSA-2020:3185 addresses vulnerabilities that lead to potential out-of-bounds reads and writes during image parsing.
Is there a specific version to upgrade to for RHSA-2020:3185?
Yes, you should upgrade to version 5.1.1-12.el8_2 or later to mitigate the vulnerabilities addressed in RHSA-2020:3185.