CVE-2014-1859: Medium severity numpy vulnerability
Published Jan 8, 2018
·Updated
(1) core/tests/testmemmap.py, (2) core/tests/testmultiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/testio.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
Affected Software
8 affected componentsFixes available
debian/python-numpy
pip/numpy<1.8.1
1.8.1
NumPy NumPy<=1.8.0
NumPy NumPy=1.8.1-rc1
Fedoraproject Fedora=19
Fedoraproject Fedora=20
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jan 8, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:08 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2014-1859.
2
What is the severity of CVE-2014-1859?
CVE-2014-1859 has a severity rating of 5.5, which is considered medium.
3
Which software packages are affected by CVE-2014-1859?
The software packages affected by CVE-2014-1859 include python-numpy, Numpy, Fedoraproject Fedora, and Redhat Enterprise Linux.
4
How can local users exploit CVE-2014-1859?
Local users can exploit CVE-2014-1859 by using a symlink attack on a temporary file to write to arbitrary files.
5
Where can I find more information about CVE-2014-1859?
You can find more information about CVE-2014-1859 at the following references: [link]