Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-34141

Опубликовано: 17 дек. 2021
Источник: debian
EPSS Низкий

Описание

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
numpyunfixedpackage

Примечания

  • https://github.com/numpy/numpy/issues/18993

  • https://github.com/numpy/numpy/commit/eeef9d4646103c3b1afd3085f1393f2b3f9575b2 (v1.23.0.dev0)

  • Negligible security impact

EPSS

Процентиль: 21%
0.00065
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 2.2
redhat
около 4 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 5.3
nvd
больше 3 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 5.3
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.3
github
больше 3 лет назад

Incorrect Comparison in NumPy

EPSS

Процентиль: 21%
0.00065
Низкий