Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpfv-jqm9-f5jm

Опубликовано: 18 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Incorrect Comparison in NumPy

Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific string objects.

Пакеты

Наименование

numpy

pip
Затронутые версииВерсия исправления

< 1.22

1.22

EPSS

Процентиль: 20%
0.00064
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 4 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 2.2
redhat
больше 4 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 5.3
nvd
около 4 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 5.3
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 4 лет назад

An incomplete string comparison in the numpy.core component in NumPy b ...

EPSS

Процентиль: 20%
0.00064
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697