CVE-2014-1859: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.

Affected products

  • Fedoraproject Fedora: version 19 only; version 20 only
  • Numpy Numpy: up to and including 1.8.0; version 1.8.1 only
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only

Published 2018-01-08. Last modified 2026-06-17.