{"schema_version":"1.7.3","id":"SUSE-SU-2020:2057-1","published":"2020-07-27T20:26:47Z","modified":"2026-02-04T04:15:02.625377Z","related":["CVE-2016-0775","CVE-2019-16865","CVE-2019-19911","CVE-2020-10177","CVE-2020-10378","CVE-2020-10994","CVE-2020-5312","CVE-2020-5313"],"upstream":["CVE-2016-0775","CVE-2019-16865","CVE-2019-19911","CVE-2020-10177","CVE-2020-10378","CVE-2020-10994","CVE-2020-5312","CVE-2020-5313"],"summary":"Security update for python-Pillow","details":"This update for python-Pillow fixes the following issues:\n\n- Add 0019-FLI-overflow-error-fix-and-testcase.patch\n   * Fixes CVE-2016-0775, bsc#965582\n- Add 0020-Fix-OOB-reads-in-FLI-decoding.patch\n   * Fixes CVE-2020-10177, bsc#1173413\n- Add 0021-Fix-bounds-overflow-in-JPEG-2000-decoding.patch\n   * Fixes CVE-2020-10994, bsc#1173418\n- Add 0022-Fix-bounds-overflow-in-PCX-decoding.patch\n   * Fixes CVE-2020-10378, bsc#1173416\n- Add 0008-Corrected-negative-seeks.patch\n   * Fixes part of CVE-2019-16865, bsc#1153191\n- Add 0009-Make-Image.crop-an-immediate-operation.patch\n   * Fixes https://github.com/python-pillow/Pillow/issues/1077\n   * Used by 0012-Added-decompression-bomb-checks.patch\n- Add 0010-Crop-decompression.patch\n   * Used by 0012-Added-decompression-bomb-checks.patch\n- Add 0011-Added-DecompressionBombError.patch\n   * Used by 0012-Added-decompression-bomb-checks.patch\n- Add 0012-Added-decompression-bomb-checks.patch\n   * Fixes part of CVE-2019-16865, bsc#1153191\n- Add 0013-Raise-error-if-dimension-is-a-string.patch\n   * Fixes part of CVE-2019-16865, bsc#1153191\n- Add 0014-Catch-buffer-overruns.patch\n   * Fixes part of CVE-2019-16865, bsc#1153191\n- Add 0015-Catch-PCX-P-mode-buffer-overrun.patch\n   * Fixes CVE-2020-5312, bsc#1160152\n- Add 0016-Ensure-previous-FLI-frame-is-loaded.patch\n   * Fixes https://github.com/python-pillow/Pillow/issues/2649\n   * Uncovers CVE-2020-5313, bsc#1160153\n- Add 0017-Catch-FLI-buffer-overrun.patch\n   * Fixes CVE-2020-5313, bsc#1160153\n- Add 018-Invalid-number-of-bands-in-FPX-image.patch\n   * Fixes CVE-2019-19911, bsc#1160192\n","affected":[{"package":{"name":"python-Pillow","ecosystem":"SUSE:Enterprise Storage 5","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Enterprise%20Storage%205"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.1-3.9.1"}]}],"ecosystem_specific":{"binaries":[{"python-Pillow":"2.8.1-3.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2057-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20202057-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1153191"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160152"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160153"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160192"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173413"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173416"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173418"},{"type":"REPORT","url":"https://bugzilla.suse.com/965582"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-0775"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-10177"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-10378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-10994"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-5312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-5313"}]}