CVE-2014-1933

Description

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

Risk Information

Base Score
4.0
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.111

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-1932,CVE-2014-1933 are fixed in Python-pillow 2.3.1Windows
Vulnerabilities CVE-2014-1932,CVE-2014-1933 are fixed in Python-pillow for linux 2.3.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234