CVE-2014-1932
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.
Las funciones (1) load_djpeg ein JpegImagePlugin.py, (2) Ghostscript en EpsImagePlugin.py, (3) load en IptcImagePlugin.py and (4) _copy en Image.py en Python Image Library (PIL) 1.1.7 y anteriores y Pillow anterior a 2.3.1 no crean debidamente archivos temporales, lo que permite a usuarios locales sobrescribir archivos arbitrarios y obtener información sensible a través de un ataque symlink sobre el archivo temporal.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-02-10 CVE Reserved
- 2014-04-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2014/02/11/1 | Mailing List | |
http://www.securityfocus.com/bid/65511 | Vdb Entry | |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737059 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://github.com/python-imaging/Pillow/commit/4e9f367dfd3f04c8f5d23f7f759ec12782e10ee7 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2014-05/msg00002.html | 2017-07-01 | |
http://www.ubuntu.com/usn/USN-2168-1 | 2017-07-01 | |
https://security.gentoo.org/glsa/201612-52 | 2017-07-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Python Search vendor "Python" | Pillow Search vendor "Python" for product "Pillow" | <= 2.3.0 Search vendor "Python" for product "Pillow" and version " <= 2.3.0" | - |
Affected
| ||||||
Pythonware Search vendor "Pythonware" | Python Imaging Library Search vendor "Pythonware" for product "Python Imaging Library" | <= 1.1.7 Search vendor "Pythonware" for product "Python Imaging Library" and version " <= 1.1.7" | - |
Affected
|