MGASA-2013-0330
Dashboard / Vulnerabilities / MGASA-2013-0330
Summary: Updated python-scipy packages fix a security vulnerability and missing deps
Details: Updated python-scipy package fixes security vulnerability: scipy.weave will use /tmp/[username] as persistent storage (cache), but it does not check whether or not this directory already exists, does not check whether it is a directory or a symlink, and also does not verify permissions or ownership, which could allow someone to place code in this directory that would be executed as the user running scipy.weave (CVE-2013-4251). The update also adds some missing dependencies.
References: https://advisories.mageia.org/MGASA-2013-0330.html, https://lists.fedoraproject.org/pipermail/package-announce/2013-October/119771.html, https://bugs.mageia.org/show_bug.cgi?id=11555
Affected packages
Package
Name: python-scipy
Purl: pkg:rpm/mageia/python-scipy?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
