Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r854-96gq-rfg3

Опубликовано: 18 мая 2020
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 4

Описание

Pillow Temporary file name leakage

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

< 2.3.1

2.3.1

EPSS

Процентиль: 30%
0.00111
Низкий

5.1 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 12 лет назад

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

redhat
около 12 лет назад

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

nvd
почти 12 лет назад

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

debian
почти 12 лет назад

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python ...

EPSS

Процентиль: 30%
0.00111
Низкий

5.1 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-200