CVE-2014-1859: Fedoraproject Fedora
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
Affected products
- Fedoraproject Fedora: version 19 only; version 20 only
- Numpy Numpy: up to and including 1.8.0; version 1.8.1 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
Published 2018-01-08. Last modified 2026-06-17.