CVE-2014-1859
published 2018-01-08CVE-2014-1859: (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to…
PriorityP424medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.47%
37.7th percentile
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| numpy | numpy | <= 1.8.0 | — |
| numpy | numpy | — | — |
| numpy | numpy | >= 0 < 1.8.1 | 1.8.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Numpy arbitrary file write via symlink attack
ghsa·2022-05-14
CVE-2014-1859 [HIGH] CWE-59 Numpy arbitrary file write via symlink attack
Numpy arbitrary file write via symlink attack
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
OSV
Numpy arbitrary file write via symlink attack
osv·2022-05-14
CVE-2014-1859 [HIGH] Numpy arbitrary file write via symlink attack
Numpy arbitrary file write via symlink attack
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
OSV
CVE-2014-1859: (1) core/tests/test_memmap
osv·2018-01-08·CVSS 5.5
CVE-2014-1859 [MEDIUM] CVE-2014-1859: (1) core/tests/test_memmap
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
Red Hat
numpy: f2py insecure temporary file use
vendor_redhat·2014-02-05·CVSS 5.5
CVE-2014-1859 [MEDIUM] CWE-377 numpy: f2py insecure temporary file use
numpy: f2py insecure temporary file use
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: numpy (OpenShift Enterprise 1) - Will not fix
Package: numpy (Red Hat Enterprise Linux 6) - Will not fix
Package: numpy (Red Hat Enterprise Linux 7) - Will not fix
Package: numpy (Red Hat Enterprise MRG 1) - Will not fix
Package
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-6551 mysql: unspecified vulnerability related to CLIENT:MYSQLADMIN (CPU October 2014)
bugzilla·2014-10-16·CVSS 2.1
CVE-2014-6551 [LOW] CVE-2014-6551 mysql: unspecified vulnerability related to CLIENT:MYSQLADMIN (CPU October 2014)
CVE-2014-6551 mysql: unspecified vulnerability related to CLIENT:MYSQLADMIN (CPU October 2014)
The following issue has been fixed in MySQL:
"Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier
and 5.6.19 and earlier allows local users to affect confidentiality
via vectors related to CLIENT:MYSQLADMIN."
References:
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 1153469]
---
Created mariadb tracking bugs for this issue:
Affects: fedora-all [bug 1160551]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:1859 https://rhn.redhat.com/errata/RHSA-2014-1859.html
---
This issue has been addressed in t
Bugzilla
CVE-2014-1858 CVE-2014-1859 numpy: f2py insecure temporary file use [epel-5]
bugzilla·2014-02-13·CVSS 5.5
CVE-2014-1858 [MEDIUM] CVE-2014-1858 CVE-2014-1859 numpy: f2py insecure temporary file use [epel-5]
CVE-2014-1858 CVE-2014-1859 numpy: f2py insecure temporary file use [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for
Bugzilla
CVE-2014-1858 CVE-2014-1859 python26-numpy: numpy: f2py insecure temporary file use [epel-5]
bugzilla·2014-02-13·CVSS 5.5
CVE-2014-1858 [MEDIUM] CVE-2014-1858 CVE-2014-1859 python26-numpy: numpy: f2py insecure temporary file use [epel-5]
CVE-2014-1858 CVE-2014-1859 python26-numpy: numpy: f2py insecure temporary file use [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5
Bugzilla
CVE-2014-1858 CVE-2014-1859 numpy: f2py insecure temporary file use
bugzilla·2014-02-06·CVSS 5.5
CVE-2014-1858 [MEDIUM] CVE-2014-1858 CVE-2014-1859 numpy: f2py insecure temporary file use
CVE-2014-1858 CVE-2014-1859 numpy: f2py insecure temporary file use
Jakub Wilk found that f2py insecurely used a temporary file. A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file accessible to the user running f2py.
The original report in the Debian bug tracking system (http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737778) notes the issue is in numpy/f2py/__init__.py:
from numpy.distutils.exec_command import exec_command
import tempfile
if source_fn is None:
fname = os.path.join(tempfile.mktemp()+'.f')
else:
fname = source_fn
f = open(fname,'w')
Discussion:
CVE request: http://www.openwall.com/lists/oss-security/2014/02/06/3
No patch yet so I have not bothered to file any Fedora trackers etc yet
---
(In reply to Murray McAllister
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128358.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128781.htmlhttp://www.openwall.com/lists/oss-security/2014/02/08/3http://www.securityfocus.com/bid/65440https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737778https://bugzilla.redhat.com/show_bug.cgi?id=1062009https://exchange.xforce.ibmcloud.com/vulnerabilities/91317https://github.com/numpy/numpy/blob/maintenance/1.8.x/doc/release/1.8.1-notes.rsthttps://github.com/numpy/numpy/commit/0bb46c1448b0d3f5453d5182a17ea7ac5854ee15https://github.com/numpy/numpy/pull/4262http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128358.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128781.htmlhttp://www.openwall.com/lists/oss-security/2014/02/08/3http://www.securityfocus.com/bid/65440https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737778https://bugzilla.redhat.com/show_bug.cgi?id=1062009https://exchange.xforce.ibmcloud.com/vulnerabilities/91317https://github.com/numpy/numpy/blob/maintenance/1.8.x/doc/release/1.8.1-notes.rsthttps://github.com/numpy/numpy/commit/0bb46c1448b0d3f5453d5182a17ea7ac5854ee15https://github.com/numpy/numpy/pull/4262
2018-01-08
Published