Python numpy Package Insecure File Creation Vulnerability
BID:65360
Info
Python numpy Package Insecure File Creation Vulnerability
| Bugtraq ID: | 65360 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 06 2014 12:00AM |
| Updated: | Feb 06 2014 12:00AM |
| Credit: | Jakub Wilk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Python numpy Package Insecure File Creation Vulnerability
Python numpy package is prone to an insecure file-creation vulnerability.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Python numpy 1.3 through 1.7 are vulnerable.
Python numpy package is prone to an insecure file-creation vulnerability.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Python numpy 1.3 through 1.7 are vulnerable.
Exploit / POC
Python numpy Package Insecure File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Python numpy Package Insecure File Creation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Python numpy Package Insecure File Creation Vulnerability
References:
References:
- python-pil: CVE-2014-1932 CVE-2014-1933 (Debian)
- Python Imaging Library (PIL) Homepage (Python)