PT-2014-4372 · Python+1 · Pillow+2

Wiredfool

·

Publicado

2014-04-03

·

Atualizado

2020-05-18

·

CVE-2014-1933

CVSS v4.0

5.1

Média

VetorAV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 2.3.1 Python Image Library (PIL) versions 1.1.7 and earlier
Description The issue in the JpegImagePlugin.py and EpsImagePlugin.py scripts makes it easier for local users to conduct symlink attacks by listing the processes. This is due to the scripts using the names of temporary files on the command line.
Recommendations For Pillow versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. For Python Image Library (PIL) versions 1.1.7 and earlier, consider upgrading to Pillow, as PIL is no longer maintained, and then update to version 2.3.1 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-1933
GHSA-R854-96GQ-RFG3
MGASA-2014-0158
MGASA-2014-0159
PYSEC-2014-23
SUSE-SU-2015:0777-1

Produtos afetados

Pillow
Python Image Library
Suse