Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m9x-pxwq-j236

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Pillow command injection

Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.5.0 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 2.5.0

2.5.0

EPSS

Процентиль: 86%
0.03008
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

ubuntu
почти 12 лет назад

Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

redhat
около 12 лет назад

Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

nvd
почти 12 лет назад

Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

debian
почти 12 лет назад

Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allo ...

EPSS

Процентиль: 86%
0.03008
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78