CVE-2014-1933
Publication date 21 February 2014
Last updated 24 July 2024
Ubuntu priority
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
Status
Package | Ubuntu Release | Status |
---|---|---|
pillow | ||
python-imaging | ||
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2168-1
- Python Imaging Library vulnerabilities
- 15 April 2014