Bug 42900 - python-imaging: Multiple issues (3.3)
python-imaging: Multiple issues (3.3)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 3.3
Other Linux
: P5 normal (vote)
: UCS 3.3-0-errata
Assigned To: Arvid Requate
Philipp Hahn
:
Depends on: 37067
Blocks: 34780
  Show dependency treegraph
 
Reported: 2016-11-08 20:29 CET by Arvid Requate
Modified: 2016-12-14 12:58 CET (History)
3 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2016-11-08 20:29:50 CET
Upstream Debian (Wheezy) package version 1.1.7-4+deb7u3 fixes:

* Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component. (CVE-2016-9189)

* Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. (CVE-2016-9190)
Comment 1 Arvid Requate univentionstaff 2016-11-17 13:42:06 CET
Currently UCS 3.3 installs the Debian package version 1.1.7-2 from UCS 3.0.
Now I've cherry picked package version 1.1.7-4+deb7u3 from errata4.1-4 (Wheezy) because the Debian packaging changes look like small enough. Package update worked (amd64).

Advisory: python-imaging.yaml
Comment 2 Philipp Hahn univentionstaff 2016-12-12 16:32:38 CET
OK: aptitude install -y '?source-package(python-imaging)~i'
OK: aptitude install -y '?source-package(python-imaging)'
OK: zless /usr/share/doc/python-imaging/changelog.Debian.gz 1.1.7-2 -> 1.1.7-4~ucs3.3.16.201611171204

OK: python-imaging.yaml
OK: errata-announce -V --only python-imaging.yaml

OK: CVE-2016-9189
OK: CVE-2016-9190
OK: CVE-2016-0775
OK: CVE-2016-2533
MISSING: CVE-2014-3589 (bug #34780 comment 1)
Comment 3 Arvid Requate univentionstaff 2016-12-12 16:42:57 CET
Added.
Comment 4 Philipp Hahn univentionstaff 2016-12-13 08:57:04 CET
OK: r75224
Comment 5 Janek Walkenhorst univentionstaff 2016-12-14 12:58:50 CET
<http://errata.software-univention.de/ucs/3.3/27.html>