(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
2018-01-08T19:29:00.297
2024-11-21T02:05:10.077
Modified
CVSSv3.0: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:P/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | numpy | numpy | ≤ 1.8.0 | Yes |
Application | numpy | numpy | 1.8.1 | Yes |
Operating System | fedoraproject | fedora | 19 | Yes |
Operating System | fedoraproject | fedora | 20 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |