CVE-2014-1933
Publication date 21 February 2014
Last updated 24 July 2024
Ubuntu priority
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
Status
Package | Ubuntu Release | Status |
---|---|---|
pillow | 13.10 saucy | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release | |
python-imaging | 13.10 saucy |
Fixed 1.1.7+2.0.0-1ubuntu1.1
|
12.10 quantal |
Fixed 1.1.7-4ubuntu0.12.10.1
|
|
12.04 LTS precise |
Fixed 1.1.7-4ubuntu0.12.04.1
|
|
10.04 LTS lucid |
Fixed 1.1.7-1ubuntu0.2
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2168-1
- Python Imaging Library vulnerabilities
- 15 April 2014