PT-2014-4372 · Python+1 · Pillow+2

Wiredfool

·

Published

2014-04-03

·

Updated

2020-05-18

·

CVE-2014-1933

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 2.3.1 Python Image Library (PIL) versions 1.1.7 and earlier
Description The issue in the JpegImagePlugin.py and EpsImagePlugin.py scripts makes it easier for local users to conduct symlink attacks by listing the processes. This is due to the scripts using the names of temporary files on the command line.
Recommendations For Pillow versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. For Python Image Library (PIL) versions 1.1.7 and earlier, consider upgrading to Pillow, as PIL is no longer maintained, and then update to version 2.3.1 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1933
GHSA-R854-96GQ-RFG3
MGASA-2014-0158
MGASA-2014-0159
PYSEC-2014-23
SUSE-SU-2015:0777-1

Affected Products

Pillow
Python Image Library
Suse