Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpfv-jqm9-f5jm

Опубликовано: 18 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Incorrect Comparison in NumPy

Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific string objects.

Пакеты

Наименование

numpy

pip
Затронутые версииВерсия исправления

< 1.22

1.22

EPSS

Процентиль: 21%
0.00065
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 2.2
redhat
около 4 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 5.3
nvd
больше 3 лет назад

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS3: 5.3
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.3
debian
больше 3 лет назад

An incomplete string comparison in the numpy.core component in NumPy b ...

EPSS

Процентиль: 21%
0.00065
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697