CVE-2014-1933

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
cpe:2.3:a:pythonware:python_imaging_library:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-04-17 14:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-1933

Mitre link : CVE-2014-1933

CVE.ORG link : CVE-2014-1933


JSON object : View

Products Affected

python

  • pillow

pythonware

  • python_imaging_library
CWE
CWE-264

Permissions, Privileges, and Access Controls