ELA-546-1 pillow security update

arbitrary code execution

2022-01-24
Packagepillow
Version2.6.1-2+deb8u7
Related CVEs CVE-2021-28675 CVE-2021-28676 CVE-2021-28677 CVE-2021-34552 CVE-2022-22815 CVE-2022-22816 CVE-2022-22817


Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service and potentially the execution of arbitrary code if malformed images are processed.



For Debian 8 jessie, these problems have been fixed in version 2.6.1-2+deb8u7.

We recommend that you upgrade your pillow packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.