Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| pillow(PyPI) | 0 | 2.5.0 | N/A |
CVSS Metrics