freedomofpress / securethenews

An automated scanner and web dashboard for tracking TLS deployment across news organizations
https://securethe.news
GNU Affero General Public License v3.0
102 stars 25 forks source link

Updates pillow #359

Closed SaptakS closed 3 years ago

SaptakS commented 3 years ago

Pillow <=8.2.0 Allows an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c. https://access.redhat.com/security/cve/cve-2021-34552