Skip to content

Pillow Temporary file name leakage

Low severity GitHub Reviewed Published May 18, 2020 to the GitHub Advisory Database • Updated Sep 5, 2023

Package

pip Pillow (pip)

Affected versions

< 2.3.1

Patched versions

2.3.1

Description

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

References

Reviewed May 18, 2020
Published to the GitHub Advisory Database May 18, 2020
Last updated Sep 5, 2023

Severity

Low

EPSS score

0.042%
(5th percentile)

Weaknesses

No CWEs

CVE ID

CVE-2014-1933

GHSA ID

GHSA-r854-96gq-rfg3

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.