Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-12852

Опубликовано: 15 авг. 2017
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1python27-numpyWill not fix
Red Hat Enterprise Linux 6numpyWill not fix
Red Hat Enterprise Linux 7numpyWill not fix
Red Hat Enterprise MRG 1numpyWill not fix
Red Hat OpenStack Platform 11 (Ocata)numpyWill not fix
Red Hat Software Collectionspython27-numpyWill not fix
Red Hat Software Collectionsrh-python34-numpyWill not fix
Red Hat Software Collectionsrh-python35-numpyWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1483686numpy: Missing input validation on empty list or ndarray in numpy.pad function

EPSS

Процентиль: 85%
0.02681
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

CVSS3: 7.5
nvd
около 9 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

CVSS3: 7.5
debian
около 9 лет назад

The numpy.pad function in Numpy 1.13.1 and older versions is missing i ...

suse-cvrf
почти 4 года назад

Security update for python-numpy

suse-cvrf
почти 9 лет назад

Initial release of python-numpy for HPC (v1.13.3, gcc)

EPSS

Процентиль: 85%
0.02681
Низкий

4 Medium

CVSS3