Skip to content

Commit ae43cda

Browse files
committed
Added release notes for python-pillow#7235
1 parent 2de1bf2 commit ae43cda

File tree

1 file changed

+8
-3
lines changed

1 file changed

+8
-3
lines changed

docs/releasenotes/10.0.0.rst

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -157,10 +157,15 @@ TODO
157157
Security
158158
========
159159

160-
TODO
161-
^^^^
160+
Limit size even if one dimension is zero
161+
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
162162

163-
TODO
163+
When performing decompression bomb checks, Pillow did not reject images with
164+
excessive width and zero height, or zero width and excessive height. That has
165+
now been fixed.
166+
167+
This effectively dates to the PIL fork, since problem images would still have
168+
been processed before Pillow started checking for decompression bombs.
164169

165170
Other Changes
166171
=============

0 commit comments

Comments
 (0)