First published: Sun Apr 27 2014(Updated: )
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/pillow | <2.5.0 | 2.5.0 |
Python Pillow | =2.3.0 | |
Pythonware Python Imaging Library | <=1.1.7 | |
=2.3.0 | ||
<=1.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.