Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1932

Опубликовано: 17 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.4

Описание

The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.

РелизСтатусПримечание
devel

released

2.3.0-1ubuntu3
lucid

DNE

precise

DNE

quantal

DNE

saucy

DNE

upstream

needed

Показывать по

РелизСтатусПримечание
devel

DNE

lucid

released

1.1.7-1ubuntu0.2
precise

released

1.1.7-4ubuntu0.12.04.1
quantal

released

1.1.7-4ubuntu0.12.10.1
saucy

released

1.1.7+2.0.0-1ubuntu1.1
upstream

needed

Показывать по

EPSS

Процентиль: 33%
0.00133
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.

nvd
почти 12 лет назад

The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.

debian
почти 12 лет назад

The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript fun ...

CVSS3: 7.7
github
больше 3 лет назад

PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles

EPSS

Процентиль: 33%
0.00133
Низкий

4.4 Medium

CVSS2

Уязвимость CVE-2014-1932