Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-12852

Опубликовано: 15 авг. 2017
Источник: redhat
CVSS3: 4

Описание

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1python27-numpyWill not fix
Red Hat Enterprise Linux 6numpyWill not fix
Red Hat Enterprise Linux 7numpyWill not fix
Red Hat Enterprise MRG 1numpyWill not fix
Red Hat OpenStack Platform 11 (Ocata)numpyWill not fix
Red Hat Software Collectionspython27-numpyWill not fix
Red Hat Software Collectionsrh-python34-numpyWill not fix
Red Hat Software Collectionsrh-python35-numpyWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1483686numpy: Missing input validation on empty list or ndarray in numpy.pad function

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

CVSS3: 7.5
nvd
больше 8 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

CVSS3: 7.5
debian
больше 8 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing i ...

suse-cvrf
около 3 лет назад

Security update for python-numpy

suse-cvrf
около 8 лет назад

Initial release of python-numpy for HPC (v1.13.3, gcc)

4 Medium

CVSS3