GHSA-cw6w-4rcx-xphc, CVE-2014-1858
pypi/numpy
Improper Input Validation
init.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.
All versions before 1.8.1
Upgrade to version 1.8.1 or above.
2022-06-19
source |