QID 981487
QID 981487: Python (pip) Security Update for Pillow (GHSA-r854-96gq-rfg3)
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r854-96gq-rfg3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-r854-96gq-rfg3 -
github.com/advisories/GHSA-r854-96gq-rfg3
CVEs related to QID 981487
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r854-96gq-rfg3 | Pillow |
|