MEDIUM 5.5 PyPI

Numpy arbitrary file write via symlink attack

GHSA-2fc2-6r4j-p65h · CVE-2014-1859 · PYSEC-2018-34

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.

Ready to move

Start Securing

Free, no credit card | First findings in minutes