CVE Vulnerabilities

CVE-2014-1933

Published: Apr 17, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

Affected Software

NameVendorStart VersionEnd Version
PillowPython*2.3.0 (including)
Python_imaging_libraryPythonware*1.1.7 (including)
PillowUbuntudevel*
PillowUbuntuupstream*
Python-imagingUbuntulucid*
Python-imagingUbuntuprecise*
Python-imagingUbuntuquantal*
Python-imagingUbuntusaucy*
Python-imagingUbuntuupstream*

References