Beveiligingsadvies

CVE-2014-1933

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2014-04-17 14:00:00
Laatst bijgewerkt 2024-08-06 09:58:15
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.