Errata overview
Errata ID 467
Date 2020-03-11
Source package pillow
Fixed in version 4.0.0-4+deb9u1
Description
This update addresses the following issues:
* Uncontrolled resource consumption in FpxImagePlugin.py (CVE-2019-19911)
* Improperly restricted operations on memory buffer in libImaging/PcxDecode.c
  (CVE-2020-5312)
* Out-of-bounds read in ImagingFliDecode when loading FLI images
  (CVE-2020-5313)
Additional notes
CVE ID CVE-2019-19911
CVE-2020-5312
CVE-2020-5313
UCS Bug number #50866