Univention Bugzilla – Bug 42900
python-imaging: Multiple issues (3.3)
Last modified: 2016-12-14 12:58:50 CET
Upstream Debian (Wheezy) package version 1.1.7-4+deb7u3 fixes: * Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component. (CVE-2016-9189) * Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. (CVE-2016-9190)
Currently UCS 3.3 installs the Debian package version 1.1.7-2 from UCS 3.0. Now I've cherry picked package version 1.1.7-4+deb7u3 from errata4.1-4 (Wheezy) because the Debian packaging changes look like small enough. Package update worked (amd64). Advisory: python-imaging.yaml
OK: aptitude install -y '?source-package(python-imaging)~i' OK: aptitude install -y '?source-package(python-imaging)' OK: zless /usr/share/doc/python-imaging/changelog.Debian.gz 1.1.7-2 -> 1.1.7-4~ucs3.3.16.201611171204 OK: python-imaging.yaml OK: errata-announce -V --only python-imaging.yaml OK: CVE-2016-9189 OK: CVE-2016-9190 OK: CVE-2016-0775 OK: CVE-2016-2533 MISSING: CVE-2014-3589 (bug #34780 comment 1)
Added.
OK: r75224
<http://errata.software-univention.de/ucs/3.3/27.html>