CVE-2014-3007

Pillow < 2.5.0 - OS Command Injection in JpegImagePlugin

Title source: llm
STIX 2.1

Description

Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

References (2)

Core 2

Scores

EPSS 0.0364
EPSS Percentile 88.0%

Details

CWE
CWE-78
Status published
Products (3)
pypi/pillow 0 - 2.5.0PyPI
python/pillow 2.3.0
pythonware/python_imaging_library < 1.1.7
Published Apr 27, 2014
Tracked Since Feb 18, 2026