Skip to content
NumPyGHSA-2fc2-6r4j-p65h

Numpy arbitrary file write via symlink attack

High5.5CVE-2014-1859 · Published May 14, 2022 · updated Oct 1, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
numpy
PyPI
< 1.8.11.8.1
Details and references

More NumPy advisories

All NumPy
DateAdvisory
May 142022Arbitrary file write in NumPy
CVE-2014-1858High5.5fixed in 1.8.1
May 132022Numpy missing input validation
CVE-2017-12852High7.5fixed in 1.13.3
May 242022Numpy Deserialization of Untrusted Data
CVE-2019-6446Critical9.8fixed in 1.16.3
Feb 82022NumPy NULL Pointer Dereference
CVE-2021-41495High7.5fixed in 1.19
Feb 82022Buffer Copy without Checking Size of Input in NumPy
CVE-2021-41496Medium5.5fixed in 1.19
Jan 72022NumPy Buffer Overflow (Disputed)
CVE-2021-33430Medium5.3fixed in 1.21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.