Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rh6-h94m-vj54

Опубликовано: 07 янв. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Incorrect Comparison in cvxopt

Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

Пакеты

Наименование

cvxopt

pip
Затронутые версииВерсия исправления

< 1.2.7

1.2.7

EPSS

Процентиль: 65%
0.01184
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

CVSS3: 7.5
nvd
больше 4 лет назад

Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

msrc
11 месяцев назад

Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

CVSS3: 7.5
debian
больше 4 лет назад

Incomplete string comparison vulnerability exits in cvxopt.org cvxop < ...

EPSS

Процентиль: 65%
0.01184
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-697