CVE Vulnerabilities

CVE-2014-1933

Published: Apr 17, 2014 | Modified: Jul 01, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

Affected Software

Name Vendor Start Version End Version
Pillow Python * 2.3.0 (including)
Python_imaging_library Pythonware * 1.1.7 (including)
Pillow Ubuntu devel *
Pillow Ubuntu upstream *
Python-imaging Ubuntu lucid *
Python-imaging Ubuntu precise *
Python-imaging Ubuntu quantal *
Python-imaging Ubuntu saucy *
Python-imaging Ubuntu upstream *

References