Skip to content

Commit

Permalink
Add release notes for 2.6.0 for #7864
Browse files Browse the repository at this point in the history
  • Loading branch information
aclark4life committed Mar 15, 2024
1 parent 4438305 commit 5b3dabb
Show file tree
Hide file tree
Showing 3 changed files with 32 additions and 3 deletions.
12 changes: 9 additions & 3 deletions docs/releasenotes/10.3.0.rst
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,13 @@ Release GIL when fetching WebP frames
Python's Global Interpreter Lock is now released when fetching WebP frames from
the libwebp decoder.

Add release notes for 2.3.1, 2.3.2, 2.5.2
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Added release notes for past releases
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

TODO
Added release notes for past releases: ``2.6.0``, ``2.5.2``,
``2.3.2``, ``2.3.1``. This effort is intended to provide a comprehensive
look at CVE data from 1995 to 2024 across three noteworthy periods:

- 1995-2010: No CVEs
- 2010-2019: A few CVEs
- 2019-2024: Many CVEs
22 changes: 22 additions & 0 deletions docs/releasenotes/2.6.0.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
2.6.0
-----

Security
========

:cve:`2014-3589`: Fix DOS attack
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

``PIL/IcnsImagePlugin.py`` in Python Imaging Library (PIL) and Pillow before 2.3.2 and
2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted
block size.

Found and reported by Andrew Drake of dropbox.com

Other Changes
=============

Relaxed precision of some tests
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

Relaxed imagedraw tests to allow slight errors for x86 vs x64.
1 change: 1 addition & 0 deletions docs/releasenotes/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,7 @@ expected to be backported to earlier versions.
3.0.0
2.8.0
2.7.0
2.6.0
2.5.2
2.3.2
2.3.1
Expand Down

0 comments on commit 5b3dabb

Please sign in to comment.