Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-1933
HistoryApr 17, 2014 - 2:55 p.m.

Command injection

2014-04-1714:55:00
PRIOn knowledge base
www.prio-n.com
6

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

CPENameOperatorVersion
pillowle2.3.0
python_imaging_libraryle1.1.7

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%