Skip to content

Commit

Permalink
Added release notes for 8.1.2
Browse files Browse the repository at this point in the history
  • Loading branch information
radarhere committed Mar 6, 2021
1 parent 608bf4f commit 2a66fa7
Show file tree
Hide file tree
Showing 3 changed files with 13 additions and 8 deletions.
8 changes: 0 additions & 8 deletions docs/releasenotes/8.1.1.rst
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
8.1.1
-----


Security
========

Expand All @@ -20,13 +19,6 @@ that could be used as a DOS attack.
:cve:`CVE-2021-25293`: There is an out-of-bounds read in ``SgiRleDecode.c``,
since Pillow 4.3.0.

There is an exhaustion of memory DOS in the BLP (:cve:`CVE-2021-27921`),
ICNS (:cve:`CVE-2021-27922`) and ICO (:cve:`CVE-2021-27923`) container formats
where Pillow did not properly check the reported size of the contained image.
These images could cause arbitrarily large memory allocations. This was reported
by Jiayi Lin, Luke Shaffer, Xinran Xie, and Akshay Ajayan of
`Arizona State University <https://www.asu.edu/>`_.


Other Changes
=============
Expand Down
12 changes: 12 additions & 0 deletions docs/releasenotes/8.1.2.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
8.1.2
-----

Security
========

There is an exhaustion of memory DOS in the BLP (:cve:`CVE-2021-27921`),
ICNS (:cve:`CVE-2021-27922`) and ICO (:cve:`CVE-2021-27923`) container formats
where Pillow did not properly check the reported size of the contained image.
These images could cause arbitrarily large memory allocations. This was reported
by Jiayi Lin, Luke Shaffer, Xinran Xie, and Akshay Ajayan of
`Arizona State University <https://www.asu.edu/>`_.
1 change: 1 addition & 0 deletions docs/releasenotes/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ expected to be backported to earlier versions.
.. toctree::
:maxdepth: 2

8.1.2
8.1.1
8.1.0
8.0.1
Expand Down

0 comments on commit 2a66fa7

Please sign in to comment.