[23:10:25] <wiredfool> our cve fix has a bug in it. If you pass in a format, it mkstemp's a file, then adds an extension to that, and then tries to save
[23:10:36] <wiredfool> which is a boneheaded mistake
[23:38:44] <aclark> wiredfool: was the pillow vuln "real" ? I don't see it in the CVE db: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-1932