MGASA-2013-0330

Source
https://advisories.mageia.org/MGASA-2013-0330.html
Import Source
https://advisories.mageia.org/MGASA-2013-0330.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0330
Upstream
  • CVE-2013-4251
Published
2013-11-20T20:22:27Z
Modified
2026-04-16T06:25:04Z
Summary
Updated python-scipy packages fix a security vulnerability and missing deps
Details

Updated python-scipy package fixes security vulnerability:

scipy.weave will use /tmp/[username] as persistent storage (cache), but it does not check whether or not this directory already exists, does not check whether it is a directory or a symlink, and also does not verify permissions or ownership, which could allow someone to place code in this directory that would be executed as the user running scipy.weave (CVE-2013-4251).

The update also adds some missing dependencies.

References
Credits

Affected packages

Mageia:2 / python-scipy

Package

Name
python-scipy
Purl
pkg:rpm/mageia/python-scipy?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.0-3.4.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0330.json"

Mageia:3 / python-scipy

Package

Name
python-scipy
Purl
pkg:rpm/mageia/python-scipy?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.0-7.3.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0330.json"