Lucene search

K
osvGoogleOSV:GHSA-2FC2-6R4J-P65H
HistoryMay 14, 2022 - 1:08 a.m.

Numpy arbitrary file write via symlink attack

2022-05-1401:08:34
Google
osv.dev
9
numpy
symlink attack
arbitrary file write
security issue

EPSS

0

Percentile

5.1%

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.