2.1
CVSSv2

CVE-2014-1859

Published: 08/01/2018 Updated: 22/04/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy prior to 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

numpy numpy

numpy numpy 1.8.1

redhat enterprise linux 7.0

redhat enterprise linux 6.0

fedoraproject fedora 19

fedoraproject fedora 20

Vendor Advisories

Debian Bug report logs - #737778 python-numpy: insecure use of /tmp (CVE-2014-1858 CVE-2014-1859) Package: python-numpy; Maintainer for python-numpy is Sandro Tosi <morph@debianorg>; Source for python-numpy is src:python-numpy (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Wed, 5 Feb 2014 21 ...
f2py insecurely uses a temporary file A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file accessible to the user running f2py ...
(1) core/tests/test_memmappy, (2) core/tests/test_multiarraypy, (3) f2py/f2py2epy, and (4) lib/tests/test_iopy in NumPy before 181 allow local users to write to arbitrary files via a symlink attack on a temporary file ...