V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2014-1933
DEB
Low

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses t…

CVSS
2.1
Low
EPSS
0.00
p29
Published
2014-01-01
Updated
2014-01-01
Description

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

Tags · CWE
LPE
CWE-214
CWE-264
Affected products
Pillow ≤ 2.3.0Python_imaging_library ≤ 1.1.7
CVSS vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.001 · p29
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
pillowTracked
python-imagingTracked
python-imagingTracked
python-imagingTracked
pillow*Tracked
python_imaging_library*Tracked
Source databases
DEB
CVE