Skip to content

Commit

Permalink
Add release notes for 8.0.1
Browse files Browse the repository at this point in the history
  • Loading branch information
hugovk committed Oct 22, 2020
1 parent 50f0add commit 558b2e6
Show file tree
Hide file tree
Showing 3 changed files with 30 additions and 0 deletions.
6 changes: 6 additions & 0 deletions CHANGES.rst
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,12 @@ Changelog (Pillow)
- Support raw rgba8888 for DDS #4760
[qiankanglai]

8.0.1 (2020-10-22)
------------------

- Update FreeType used in binary wheels to 2.10.4 to fix CVE-2020-15999.
[radarhere]

8.0.0 (2020-10-15)
------------------

Expand Down
23 changes: 23 additions & 0 deletions docs/releasenotes/8.0.1.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
8.0.1
-----

Security
========

Update FreeType used in binary wheels to `2.10.4`_ to fix CVE-2020-15999_:

- A heap buffer overflow has been found in the handling of embedded PNG bitmaps,
introduced in FreeType version 2.6.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999

If you use option ``FT_CONFIG_OPTION_USE_PNG`` you should upgrade immediately.

Before Pillow 8.0.0 bitmap fonts were disabled with ``FT_LOAD_NO_BITMAP``, but it is not
clear if this prevents the exploit and we recommend updating to Pillow 8.0.1.

Pillow 8.0.0 and earlier are potentially vulnerable releases, including the last release
to support Python 2.7, namely Pillow 6.2.2.

.. _2.10.4: https://sourceforge.net/projects/freetype/files/freetype2/2.10.4/
.. _CVE-2020-15999: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999
1 change: 1 addition & 0 deletions docs/releasenotes/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ expected to be backported to earlier versions.
.. toctree::
:maxdepth: 2

8.0.1
8.0.0
7.2.0
7.1.2
Expand Down

0 comments on commit 558b2e6

Please sign in to comment.