CVE-2013-4251Improper Privilege Management in Scipy

Severity
7.8HIGHNVD
EPSS
0.1%
top 75.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 5

Description

The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDscipy/scipy< 0.12.1
PyPIscipy/scipy< 0.12.1+1
CVEListV5scipy/scipybefore 0.12.1

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 18, 19, 20, Enterprise Linux 6.0

Patches

🔴Vulnerability Details

3
GHSA
SciPy creates insecure temporary directories2022-05-05
OSV
SciPy creates insecure temporary directories2022-05-05
OSV
CVE-2013-4251: The scipy2019-11-04

📋Vendor Advisories

1
Red Hat
scipy: weave /tmp and current directory issues2013-10-10

💬Community

3
Bugzilla
CVE-2013-4251 scipy: weave /tmp and current directory issues [fedora-all]2013-10-11
Bugzilla
CVE-2013-4251 scipy: weave /tmp and current directory issues [epel-5]2013-10-11
Bugzilla
CVE-2013-4251 scipy: weave /tmp and current directory issues2013-02-28