Closed Bug 1684724 Opened 4 years ago Closed 4 years ago

[wpt-sync] Sync PR 27028 - Update pillow to 8.1.0

Categories

(Testing :: web-platform-tests, task, P4)

task

Tracking

(firefox86 fixed)

RESOLVED FIXED
86 Branch
Tracking Status
firefox86 --- fixed

People

(Reporter: wpt-sync, Unassigned)

References

()

Details

(Whiteboard: [wptsync downstream])

Sync web-platform-tests PR 27028 into mozilla-central (this bug is closed when the sync is complete).

PR: https://github.com/web-platform-tests/wpt/pull/27028
Details from upstream follow.

b'pyup-bot <github-bot@pyup.io>' wrote:

Update pillow to 8.1.0

This PR updates pillow from 8.0.1 to 8.1.0.

<details>
<summary>Changelog</summary>

### 8.1.0
```
------------------
  • Fix TIFF OOB Write error. CVE-2020-35654 5175
    [wiredfool]

  • Fix for Read Overflow in PCX Decoding. CVE-2020-35653 5174
    [wiredfool, radarhere]

  • Fix for SGI Decode buffer overrun. CVE-2020-35655 5173
    [wiredfool, radarhere]

  • Fix OOB Read when saving GIF of xsize=1 5149
    [wiredfool]

  • Makefile updates 5159
    [wiredfool, radarhere]

  • Add support for PySide6 5161
    [hugovk]

  • Use disposal settings from previous frame in APNG 5126
    [radarhere]

  • Added exception explaining that repr_png saves to PNG 5139
    [radarhere]

  • Use previous disposal method in GIF load_end 5125
    [radarhere]

  • Allow putpalette to accept 1024 integers to include alpha values 5089
    [radarhere]

  • Fix OOB Read when writing TIFF with custom Metadata 5148
    [wiredfool]

  • Added append_images support for ICO 4568
    [ziplantil, radarhere]

  • Block TIFFTAG_SUBIFD 5120
    [radarhere]

  • Fixed dereferencing potential null pointers 5108, 5111
    [cgohlke, radarhere]

  • Deprecate FreeType 2.7 5098
    [hugovk, radarhere]

  • Moved warning to end of execution 4965
    [radarhere]

  • Removed unused fromstring and tostring C methods 5026
    [radarhere]

  • init() if one of the formats is unrecognised 5037
    [radarhere]

  • Moved string_dimension CVE image to pillow-depends 4993
    [radarhere]

  • Support raw rgba8888 for DDS 4760
    [qiankanglai]

    
    
    

</details>

<details>
<summary>Links</summary>

Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → INVALID
Status: RESOLVED → REOPENED
Resolution: INVALID → ---
Test result changes from PR not available.
Pushed by wptsync@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/7fca0442a20a [wpt PR 27028] - Update pillow to 8.1.0, a=testonly
Status: REOPENED → RESOLVED
Closed: 4 years ago4 years ago
Resolution: --- → FIXED
Target Milestone: --- → 86 Branch
You need to log in before you can comment on or make changes to this bug.