QID 994910
Date Published: 2023-08-21
QID 994910: Python (Pip) Security Update for pillow (GHSA-x895-2wrm-hvp7)
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-x895-2wrm-hvp7 for updates and patch information.
Vendor References
- GHSA-x895-2wrm-hvp7 -
github.com/advisories/GHSA-x895-2wrm-hvp7
CVEs related to QID 994910
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x895-2wrm-hvp7 | pillow |
|