Link Following Affecting numpy package, versions <1:1.7.2-8.10.amzn1


Severity

Recommended
low

Based on Amazon Linux security rating.

Threat Intelligence

EPSS
0.04% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-AMZN201803-NUMPY-1672613
  • published27 Sept 2021
  • disclosed8 Jan 2018

Introduced: 8 Jan 2018

CVE-2014-1859  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade Amazon-Linux:2018.03 numpy to version 1:1.7.2-8.10.amzn1 or higher.
This issue was patched in ALAS-2014-302.

NVD Description

Note: Versions mentioned in the description apply only to the upstream numpy package and not the numpy package as distributed by Amazon-Linux. See How to fix? for Amazon-Linux:2018.03 relevant fixed versions and status.

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.

CVSS Scores

version 3.1