f2py insecurely used a temporary file. A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file accessible to the user running f2py (CVE-2014-1858, CVE-2014-1859).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2014-0089.json"