Debian Package Tracker
Register | Log in
Subscribe

pillow

Choose email to subscribe with

general
  • source: pillow (main)
  • version: 9.4.0-1.1
  • maintainer: Matthias Klose (DMD)
  • arch: all any
  • std-ver: 4.6.1
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.0.0-4+deb9u1
  • o-o-sec: 4.0.0-4+deb9u4
  • oldstable: 5.4.1-2+deb10u3
  • old-sec: 5.4.1-2+deb10u3
  • stable: 8.1.2+dfsg-0.3+deb11u1
  • stable-sec: 8.1.2+dfsg-0.3+deb11u1
  • testing: 9.4.0-1.1
  • unstable: 9.4.0-1.1
versioned links
  • 4.0.0-4+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.0.0-4+deb9u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.4.1-2+deb10u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.1.2+dfsg-0.3+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 9.4.0-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-pil-doc
  • python3-pil (4 bugs: 0, 4, 0, 0)
  • python3-pil.imagetk
action needed
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs, consider including or untagging them.
Created: 2022-07-27 Last update: 2023-03-26 09:03
lintian reports 38 warnings normal
Lintian reports 38 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-01-27 Last update: 2023-02-18 17:08
debian/patches: 7 patches to forward upstream low

Among the 7 debian patches available in version 9.4.0-1.1 of the package, we noticed the following issues:

  • 7 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
3 low-priority security issues in bullseye low

There are 3 open security issues in bullseye.

2 issues left for the package maintainer to handle:
  • CVE-2021-23437: (needs triaging) The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
  • CVE-2022-45198: (needs triaging) Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).

You can find information about how to handle these issues in the security team's documentation.

1 ignored issue:
  • CVE-2022-24303: Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Created: 2022-07-04 Last update: 2023-01-29 13:50
Build log checks report 1 warning low
Build log checks report 1 warning
Created: 2022-07-23 Last update: 2022-07-23 22:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-05-11 Last update: 2023-01-26 22:46
news
[rss feed]
  • [2023-01-30] pillow 9.4.0-1.1 MIGRATED to testing (Debian testing watch)
  • [2023-01-26] Accepted pillow 9.4.0-1.1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2023-01-09] pillow 9.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-03] Accepted pillow 9.4.0-1 (source) into unstable (Matthias Klose)
  • [2022-12-31] pillow 9.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-26] Accepted pillow 9.3.0-1 (source) into unstable (Matthias Klose)
  • [2022-11-04] pillow 9.2.0-1.1 MIGRATED to testing (Debian testing watch)
  • [2022-10-28] Accepted pillow 9.2.0-1.1 (source) into unstable (Nilesh Patra)
  • [2022-07-26] pillow 9.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-17] Accepted pillow 9.2.0-1 (source) into unstable (Matthias Klose)
  • [2022-06-11] pillow 9.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-05-27] Accepted pillow 9.1.1-1 (source) into unstable (Matthias Klose)
  • [2022-04-04] Accepted pillow 9.1.0-1 (source) into unstable (Matthias Klose)
  • [2022-03-16] pillow 9.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-02-18] Accepted pillow 9.0.1-1 (source) into unstable (Matthias Klose)
  • [2022-02-05] Accepted pillow 5.4.1-2+deb10u3 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2022-01-29] pillow 9.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-23] Accepted pillow 4.0.0-4+deb9u4 (source) into oldoldstable (Emilio Pozuelo Monfort)
  • [2022-01-22] Accepted pillow 8.1.2+dfsg-0.3+deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2022-01-21] Accepted pillow 8.1.2+dfsg-0.3+deb11u1 (source) into stable-security->embargoed, stable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2022-01-21] Accepted pillow 5.4.1-2+deb10u3 (source) into oldstable->embargoed, oldstable (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2022-01-10] Accepted pillow 9.0.0-1 (source) into unstable (Matthias Klose)
  • [2021-12-01] pillow 8.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-11-25] Accepted pillow 8.4.0-1 (source) into unstable (Matthias Klose)
  • [2021-10-25] pillow 8.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-11] Accepted pillow 8.3.2-1 (source) into unstable (Matthias Klose)
  • [2021-09-15] Accepted pillow 8.1.2+dfsg-1 (source) into unstable (Matthias Klose)
  • [2021-07-25] pillow 8.1.2+dfsg-0.3 MIGRATED to testing (Debian testing watch)
  • [2021-07-22] Accepted pillow 4.0.0-4+deb9u3 (source) into oldstable (Neil Williams)
  • [2021-07-20] Accepted pillow 8.1.2+dfsg-0.3 (source) into unstable (Neil Williams)
  • 1
  • 2
bugs [bug history graph]
  • all: 5 7
  • RC: 0
  • I&N: 4 6
  • M&W: 1
  • F&P: 0
  • patch: 2
links
  • homepage
  • lintian (0, 38)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 9.4.0-1.1build1
  • 16 bugs

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing