Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

Pillow command injection

GHSA-8m9x-pxwq-j236 · CVE-2014-3007 · PYSEC-2014-87

Published · Modified

Description

Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.5.0 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

Ready to move

Start Securing

Free, no credit card | First findings in minutes