CVE-2014-1932: High severity Python Pillow vulnerability
The (1) loaddjpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.
Other sources
The (1) loaddjpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pillowto a version that resolves this vulnerability.Fixed in 2.3.1 - Upgrade
Upgrade
debian/pillowto a version that resolves this vulnerability.Fixed in 8.1.2+dfsg-0.3+deb11u2Fixed in 9.4.0-1.1+deb12u1Fixed in 11.1.0-5
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1932?
CVE-2014-1932 has been classified as a moderate severity vulnerability.
How do I fix CVE-2014-1932?
To fix CVE-2014-1932, upgrade Pillow to version 2.3.1 or later.
Which versions of Pillow are affected by CVE-2014-1932?
CVE-2014-1932 affects Pillow versions earlier than 2.3.1.
What software does CVE-2014-1932 impact?
CVE-2014-1932 impacts the Python Imaging Library (PIL) version 1.1.7 and earlier, as well as Pillow versions before 2.3.1.
Is CVE-2014-1932 present in Debian packages?
Yes, CVE-2014-1932 is present in specific Debian releases of Pillow prior to version 8.1.2+dfsg-0.3+deb11u2.