<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for python-Pillow</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2015:0777-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2015-04-22T14:27:27Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2015-04-22T14:27:27Z</InitialReleaseDate>
    <CurrentReleaseDate>2015-04-22T14:27:27Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for python-Pillow</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
python-pillow has been updated to 2.7.0 to fix three security issues.

The following vulnerabilities have been fixed:

    * CVE-2014-9601: Remote attackers could have caused a denial of service
      via a compressed text chunk in a PNG image that has a large size when
      it is decompressed.
    * CVE-2014-3598: Remote attackers could have caused a denial of service
      using specially crafted image files via Jpeg2KImagePlugin.
    * CVE-2014-3589: Remote attackers could have caused a denial of service
      using specially crafted image files via IcnsImagePlugin.
    * CVE-2014-1932: A local user could have overwritten arbitrary files
      and obtain sensitive information via a symlink attack on the
      temporary file.
    * CVE-2014-1933: A local user could have gained information helpful for
      symlink attacks by listing process information which uses the names
      of temporary files on the command line.

Security Issues:

    * CVE-2014-9601
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9601&gt;
    * CVE-2014-3598
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3598&gt;
    * CVE-2014-3589
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3589&gt;
    * CVE-2014-1932
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1932&gt;
    * CVE-2014-1933
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1933&gt;

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">sleclo50sp3-python-Pillow</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150777-1/</URL>
      <Description>Link for SUSE-SU-2015:0777-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2015-April/001361.html</URL>
      <Description>E-Mail link for SUSE-SU-2015:0777-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/921566</URL>
      <Description>SUSE Bug 921566</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-1932/</URL>
      <Description>SUSE CVE CVE-2014-1932 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-1933/</URL>
      <Description>SUSE CVE CVE-2014-1933 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3589/</URL>
      <Description>SUSE CVE CVE-2014-3589 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3598/</URL>
      <Description>SUSE CVE CVE-2014-3598 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-9601/</URL>
      <Description>SUSE CVE CVE-2014-9601 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 5">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 5">
        <FullProductName ProductID="SUSE OpenStack Cloud 5" CPE="cpe:/o:suse:cloud:5">SUSE OpenStack Cloud 5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="python-Pillow-2.7.0-0.7.1">
      <FullProductName ProductID="python-Pillow-2.7.0-0.7.1">python-Pillow-2.7.0-0.7.1</FullProductName>
    </Branch>
    <Relationship ProductReference="python-Pillow-2.7.0-0.7.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 5">
      <FullProductName ProductID="SUSE OpenStack Cloud 5:python-Pillow-2.7.0-0.7.1">python-Pillow-2.7.0-0.7.1 as a component of SUSE OpenStack Cloud 5</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.</Note>
    </Notes>
    <CVE>CVE-2014-1932</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE OpenStack Cloud 5:python-Pillow-2.7.0-0.7.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.4</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150777-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-1932.html</URL>
        <Description>CVE-2014-1932</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/863541</URL>
        <Description>SUSE Bug 863541</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/921566</URL>
        <Description>SUSE Bug 921566</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.</Note>
    </Notes>
    <CVE>CVE-2014-1933</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE OpenStack Cloud 5:python-Pillow-2.7.0-0.7.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150777-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-1933.html</URL>
        <Description>CVE-2014-1933</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/863541</URL>
        <Description>SUSE Bug 863541</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/921566</URL>
        <Description>SUSE Bug 921566</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.</Note>
    </Notes>
    <CVE>CVE-2014-3589</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE OpenStack Cloud 5:python-Pillow-2.7.0-0.7.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150777-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3589.html</URL>
        <Description>CVE-2014-3589</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/921566</URL>
        <Description>SUSE Bug 921566</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.</Note>
    </Notes>
    <CVE>CVE-2014-3598</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE OpenStack Cloud 5:python-Pillow-2.7.0-0.7.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150777-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3598.html</URL>
        <Description>CVE-2014-3598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/921566</URL>
        <Description>SUSE Bug 921566</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.</Note>
    </Notes>
    <CVE>CVE-2014-9601</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE OpenStack Cloud 5:python-Pillow-2.7.0-0.7.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150777-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-9601.html</URL>
        <Description>CVE-2014-9601</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/921566</URL>
        <Description>SUSE Bug 921566</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
