Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frgw-fgh6-9g52

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Numpy missing input validation

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

Пакеты

Наименование

numpy

pip
Затронутые версииВерсия исправления

< 1.13.3

1.13.3

EPSS

Процентиль: 74%
0.00808
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

CVSS3: 4
redhat
больше 8 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

CVSS3: 7.5
nvd
больше 8 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

CVSS3: 7.5
debian
больше 8 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing i ...

suse-cvrf
около 3 лет назад

Security update for python-numpy

EPSS

Процентиль: 74%
0.00808
Низкий

7.5 High

CVSS3

Дефекты

CWE-835