UbuntuUpdates.org

Package "python3-pil.imagetk"

Name: python3-pil.imagetk

Description:

Python Imaging Library - ImageTk Module (Python3)

Latest version: 11.3.0-1ubuntu1.2
Release: questing (25.10)
Level: security
Repository: universe
Head package: pillow
Homepage: http://python-pillow.github.io/

Links


Download "python3-pil.imagetk"


Other versions of "python3-pil.imagetk" in Questing

Repository Area Version
base universe 11.3.0-1ubuntu1
updates universe 11.3.0-1ubuntu1.2

Changelog

Version: 11.3.0-1ubuntu1.2 2026-04-27 14:11:15 UTC

  pillow (11.3.0-1ubuntu1.2) questing-security; urgency=medium

  * SECURITY UPDATE: unbounded memory consumption via FITS image
    - debian/patches/CVE-2026-40192.patch: only read as much data from
      gzip-decompressed data as necessary in src/PIL/FitsImagePlugin.py.
    - CVE-2026-40192

 -- Marc Deslauriers <email address hidden> Tue, 21 Apr 2026 07:54:05 -0400

Source diff to previous version
CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image,

Version: 11.3.0-1ubuntu1.1 2026-02-17 16:08:40 UTC

  pillow (11.3.0-1ubuntu1.1) questing-security; urgency=medium

  * SECURITY UPDATE: OOB write via PSD image
    - debian/patches/CVE-2026-25990.patch: fix OOB Write with invalid tile
      extents in Tests/test_imagefile.py, src/decode.c, src/encode.c.
    - CVE-2026-25990

 -- Marc Deslauriers <email address hidden> Fri, 13 Feb 2026 08:40:02 -0500

CVE-2026-25990 Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image.



About   -   Send Feedback to @ubuntu_updates