Yarden Porat discovered that missing input sanitising in the PSD support of Pillow, a Python imaging library, could result in denial of service or the execution of arbitrary code if malformed images are processed.
The oldstable distribution (bookworm) is not affected.
https://security-tracker.debian.org/tracker/DSA-6147-1
Continue reading...
The oldstable distribution (bookworm) is not affected.
https://security-tracker.debian.org/tracker/DSA-6147-1
Continue reading...

