| Name | CVE-2014-3007 | 
| Description | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py. | 
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
| Debian Bugs | 737059 | 
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status | 
|---|
| pillow (PTS) | bullseye (security), bullseye | 8.1.2+dfsg-0.3+deb11u2 | fixed | 
|  | bookworm, bookworm (security) | 9.4.0-1.1+deb12u1 | fixed | 
|  | trixie | 11.1.0-5 | fixed | 
|  | forky | 11.3.0-1 | fixed | 
|  | sid | 12.0.0-1 | fixed | 
The information below is based on the following data on fixed versions.
Notes
[squeeze] - python-imaging <no-dsa> (Minor issue)
[wheezy] - python-imaging <no-dsa> (Minor issue)
details what is covered exactly by this CVE relating to CVE-2014-1932 and CVE-2014-1933 is missing