CVE-2014-1933: Infoleak
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Pillowto a version that resolves this vulnerability.Fixed in 2.3.1 - Upgrade
Upgrade
debian/pillowto a version that resolves this vulnerability.Fixed in 8.1.2+dfsg-0.3+deb11u2Fixed in 9.4.0-1.1+deb12u1Fixed in 11.1.0-5
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1933?
CVE-2014-1933 is classified as a moderate severity vulnerability.
How do I fix CVE-2014-1933?
To fix CVE-2014-1933, upgrade Pillow to version 2.3.1 or later or update the Python Imaging Library to version 1.1.7 or later.
What security risks are associated with CVE-2014-1933?
CVE-2014-1933 allows local users to conduct symlink attacks, potentially compromising system security.
Which versions of Pillow are affected by CVE-2014-1933?
Pillow versions prior to 2.3.1 are affected by CVE-2014-1933.
Which versions of the Python Imaging Library are vulnerable to CVE-2014-1933?
Vulnerable versions of the Python Imaging Library include 1.1.7 and earlier.