Skip to content

Commit a632b7a

Browse files
committed
Added release notes for #6842
1 parent 009bbe2 commit a632b7a

File tree

1 file changed

+7
-27
lines changed

1 file changed

+7
-27
lines changed

docs/releasenotes/9.4.0.rst

Lines changed: 7 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -1,30 +1,6 @@
11
9.4.0
22
-----
33

4-
Backwards Incompatible Changes
5-
==============================
6-
7-
TODO
8-
^^^^
9-
10-
TODO
11-
12-
Deprecations
13-
============
14-
15-
TODO
16-
^^^^
17-
18-
TODO
19-
20-
API Changes
21-
===========
22-
23-
TODO
24-
^^^^
25-
26-
TODO
27-
284
API Additions
295
=============
306

@@ -96,10 +72,14 @@ When saving a JPEG image, a comment can now be written from
9672
Security
9773
========
9874

99-
TODO
100-
^^^^
75+
Fix memory DOS in ImageFont
76+
^^^^^^^^^^^^^^^^^^^^^^^^^^^
10177

102-
TODO
78+
A corrupt or specially crafted TTF font could have font metrics that lead to
79+
unreasonably large sizes when rendering text in font. ``ImageFont.py`` did not
80+
check the image size before allocating memory for it. This dates to the PIL
81+
fork. Pilllow 8.2.0 added a check for large sizes, but did not consider the
82+
case where one dimension was zero.
10383

10484
Other Changes
10585
=============

0 commit comments

Comments
 (0)