aboutsummaryrefslogtreecommitdiffstats
path: root/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb
diff options
context:
space:
mode:
authorTrevor Gamblin <trevor.gamblin@windriver.com>2022-01-28 13:51:00 -0500
committerArmin Kuster <akuster808@gmail.com>2022-01-30 15:13:01 -0800
commit23598caeafce0af0dde8d1339cf5edff021f6823 (patch)
tree710520a9cae4c2bcd709bd61cc293ea592362852 /meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb
parentb5a9b02a9e350beb330339841112b339b8b8c66e (diff)
downloadmeta-openembedded-23598caeafce0af0dde8d1339cf5edff021f6823.tar.gz
python3-pillow: fix CVE-2022-22815, 22816, 22817
Backport three patches from 9.0.0 upstream to fix CVES. Signed-off-by: Trevor Gamblin <trevor.gamblin@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb')
-rw-r--r--meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb3
1 files changed, 3 insertions, 0 deletions
diff --git a/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb b/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb
index 8279544a8f..4393d9356d 100644
--- a/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb
+++ b/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb
@@ -11,6 +11,9 @@ SRC_URI = "git://github.com/python-pillow/Pillow.git;branch=8.2.x;protocol=https
file://0001-Limit-sprintf-modes-to-10-characters.patch \
file://0001-Use-snprintf-instead-of-sprintf.patch \
file://0001-Raise-ValueError-if-color-specifier-is-too-long.patch \
+ file://0001-Initialize-coordinates-to-zero.patch \
+ file://0001-Handle-case-where-path-count-is-zero.patch \
+ file://0001-Restrict-builtins-for-ImageMath.eval.patch \
"
SRCREV ?= "e0e353c0ef7516979a9aedce3792596649ce4433"