ELA-259-1 pillow security update

Mutiple out-of-bounds reads

2020-08-08
Packagepillow
Version2.6.1-2+deb8u5
Related CVEs CVE-2020-10177


It was noticed that in Pillow before 7.1.0, there are multiple out-of-bounds reads in libImaging/FliDecode.c.



For Debian 8 jessie, these problems have been fixed in version 2.6.1-2+deb8u5.

We recommend that you upgrade your pillow packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.