Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f7c7-j99h-c22f

Опубликовано: 08 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Buffer Copy without Checking Size of Input in NumPy

Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values.

Пакеты

Наименование

numpy

pip
Затронутые версииВерсия исправления

<= 1.18.5

1.19

EPSS

Процентиль: 11%
0.00037
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally)

CVSS3: 5.5
redhat
больше 4 лет назад

Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally)

CVSS3: 5.5
nvd
около 4 лет назад

Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally)

CVSS3: 5.5
msrc
около 4 лет назад

Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19 which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally)

CVSS3: 5.5
debian
около 4 лет назад

Buffer overflow in the array_from_pyobj function of fortranobject.c in ...

EPSS

Процентиль: 11%
0.00037
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-120