From 23598caeafce0af0dde8d1339cf5edff021f6823 Mon Sep 17 00:00:00 2001 From: Trevor Gamblin Date: Fri, 28 Jan 2022 13:51:00 -0500 Subject: python3-pillow: fix CVE-2022-22815, 22816, 22817 Backport three patches from 9.0.0 upstream to fix CVES. Signed-off-by: Trevor Gamblin Signed-off-by: Armin Kuster --- meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb | 3 +++ 1 file changed, 3 insertions(+) (limited to 'meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb') diff --git a/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb b/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb index 8279544a8f..4393d9356d 100644 --- a/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb +++ b/meta-python/recipes-devtools/python/python3-pillow_8.2.0.bb @@ -11,6 +11,9 @@ SRC_URI = "git://github.com/python-pillow/Pillow.git;branch=8.2.x;protocol=https file://0001-Limit-sprintf-modes-to-10-characters.patch \ file://0001-Use-snprintf-instead-of-sprintf.patch \ file://0001-Raise-ValueError-if-color-specifier-is-too-long.patch \ + file://0001-Initialize-coordinates-to-zero.patch \ + file://0001-Handle-case-where-path-count-is-zero.patch \ + file://0001-Restrict-builtins-for-ImageMath.eval.patch \ " SRCREV ?= "e0e353c0ef7516979a9aedce3792596649ce4433" -- cgit 1.2.3-korg