ELA-383-1 pillow security update

denial-of-service

2021-03-19
Packagepillow
Version2.6.1-2+deb8u6
Related CVEs CVE-2020-35653 CVE-2021-25290


Multiple vulnerabilities were discovered in Pillow, a Python Imaging Library. An attacker could cause a denial-of-service (DoS) with crafted image files.



For Debian 8 jessie, these problems have been fixed in version 2.6.1-2+deb8u6.

We recommend that you upgrade your pillow packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.