First published: Mon Jan 08 2018(Updated: )
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NumPy NumPy | <=1.8.0 | |
NumPy NumPy | =1.8.1-rc1 | |
Fedoraproject Fedora | =19 | |
Fedoraproject Fedora | =20 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
debian/python-numpy | ||
pip/numpy | <1.8.1 | 1.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2014-1859.
CVE-2014-1859 has a severity rating of 5.5, which is considered medium.
The software packages affected by CVE-2014-1859 include python-numpy, Numpy, Fedoraproject Fedora, and Redhat Enterprise Linux.
Local users can exploit CVE-2014-1859 by using a symlink attack on a temporary file to write to arbitrary files.
You can find more information about CVE-2014-1859 at the following references: [link]