The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-pillow-develUpgrade python-pillowUpgrade python-pillow-docUpgrade python-pillow-tkUpgrade python-pillow-saneUpgrade python-pillow-debuginfo | Oct 6, 2023 | Apr 17, 2014 |
| Debian | — | Upgrade pillow | Jul 30, 2024 | Apr 17, 2014 |
| Gentoo Linux | — | Upgrade dev-python/pillow. | Oct 30, 2017 | Apr 17, 2014 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-pillow | Dec 4, 2019 | Apr 17, 2014 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-pillow | Dec 18, 2019 | Apr 17, 2014 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-pillow | Dec 27, 2019 | Apr 17, 2014 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Apr 17, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 29, 2014 |
| Suse | — | Upgrade python-imagingUpgrade python-imaging-sane | Dec 18, 2015 | Apr 17, 2014 |
| Ubuntu | — | Upgrade python-imaging | Nov 8, 2024 | Apr 17, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub