Lack of data validation - Path Traversal In pillow
Description
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 9.0.1-1 | ||
alpine v3.15 | 8.4.0-r3 | ||
debian 14 | 9.0.1-1 | ||
pypi | 9.0.1 | ||
debian 12 | 9.0.1-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.