Lucene search

K
ubuntuUbuntuUSN-2168-1
HistoryApr 15, 2014 - 12:00 a.m.

Python Imaging Library vulnerabilities

2014-04-1500:00:00
ubuntu.com
32

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

9.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.1%

Releases

  • Ubuntu 13.10
  • Ubuntu 12.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • python-imaging - Python Imaging Library

Details

Jakub Wilk discovered that the Python Imaging Library incorrectly handled
temporary files. A local attacker could possibly use this issue to
overwrite arbitrary files, or gain access to temporary file contents.
(CVE-2014-1932, CVE-2014-1933)

OSVersionArchitecturePackageVersionFilename
Ubuntu13.10noarchpython-imaging< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython-imaging-dbg< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython-imaging-sane< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython-imaging-sane-dbg< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython-imaging-tk< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython-imaging-tk-dbg< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython3-imaging< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython3-imaging-dbg< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython3-imaging-sane< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Ubuntu13.10noarchpython3-imaging-sane-dbg< 1.1.7+2.0.0-1ubuntu1.1UNKNOWN
Rows per page:
1-10 of 301

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

9.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.1%