Executive brief
__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.
Affected products
- PyPI numpy
Junglewise Threat Intelligence
CVE-2014-1858 · Severity: low · CVSS 3 · Published 2018-01-08
Technologies: numpy (PyPI). Vendors: PyPI.
__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.