NumPy '__init__.py' Insecure Temporary File Creation Vulnerability
BID:65441
CVE-2014-1858 |Info
NumPy '__init__.py' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 65441 |
| Class: | Design Error |
| CVE: |
CVE-2014-1858 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 05 2014 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | Jakub Wilk |
| Vulnerable: |
Numpy developers NumPy 1.7.1 |
| Not Vulnerable: | |
Discussion
NumPy '__init__.py' Insecure Temporary File Creation Vulnerability
NumPy is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in obtaining sensitive information. Other attacks may also be possible.
NumPy is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in obtaining sensitive information. Other attacks may also be possible.
Exploit / POC
NumPy '__init__.py' Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
NumPy '__init__.py' Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NumPy '__init__.py' Insecure Temporary File Creation Vulnerability
References:
References:
- python-pil: CVE-2014-1932 CVE-2014-1933 (Debian)
- Python Imaging Library (PIL) Homepage (Python)
- Re: CVE request: f2py insecure temporary file use (SecLists.Org)