[Image-SIG] Serious bug in PIL's handling of PNG images

Joao S. O. Bueno gwidion at mpc.com.br
Thu Feb 17 14:07:16 CET 2011


On Thu, Feb 17, 2011 at 10:53 AM, Oliver Tonnhofer <olt at bogosoft.com> wrote:
>
> On 17.02.2011, at 13:39, Joao S. O. Bueno wrote:
>>> It's questionable if this is a serious bug. It's more a missing feature (read alpha from paletted images).
>>
>> Since the alpha in paletted PNG images is in the PNG specification,
>> and PIL does support alpha I am quite certain this can be named a
>> bug. And a severe misfeature.
>
> But by far not a serious one. Or how do you call bugs that crash your system then?

Indeed, when reading teh subject here, I  could not help thinking of a
crafted PNG to run arbitrary Python code.  :-)

  js
 -><-


More information about the Image-SIG mailing list