Описание
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
A flaw was found in SciPy, where it is vulnerable to a denial of service caused by a memory leak flaw in the Py_FindObjects() function due to a new reference not being decreased. This flaw allows a local attacker to send a specially crafted request, forcing the application to leak memory and perform a denial of service attack.
Отчет
This CVE is disputed as per upstream - https://github.com/scipy/scipy/issues/16235#issuecomment-1625361328.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | scipy | Out of support scope | ||
Red Hat Enterprise Linux 7 | scipy | Out of support scope | ||
Red Hat Enterprise Linux 8 | python27:2.7/scipy | Will not fix | ||
Red Hat Enterprise Linux 8 | python3.11-scipy | Not affected | ||
Red Hat Enterprise Linux 8 | python36:3.6/scipy | Will not fix | ||
Red Hat Enterprise Linux 8 | python39:3.9/scipy | Will not fix | ||
Red Hat Enterprise Linux 9 | python3.11-scipy | Will not fix | ||
Red Hat Enterprise Linux 9 | scipy | Will not fix | ||
Red Hat OpenShift Container Platform 4 | google-benchmark | Not affected | ||
Red Hat OpenShift Container Platform 4 | python-sortedcontainers | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
A refcounting issue which leads to potential memory leak was discovere ...
Уязвимость функции Py_FindObjects() библиотеки для языка программирования Python с открытым исходным кодом scipy, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.5 Medium
CVSS3