Описание
A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
A flaw was found in SciPy, where it is vulnerable to a denial of service caused by a use-after-free bug in the Py_FindObjects() function. By sending a specially crafted request, an attacker can cause a denial of service condition.
Отчет
This CVE is disputed as per upstream - https://github.com/scipy/scipy/issues/14713#issuecomment-1629468565
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | scipy | Out of support scope | ||
Red Hat Enterprise Linux 7 | scipy | Out of support scope | ||
Red Hat Enterprise Linux 8 | python27:2.7/scipy | Will not fix | ||
Red Hat Enterprise Linux 8 | python3.11-scipy | Not affected | ||
Red Hat Enterprise Linux 8 | python36:3.6/scipy | Will not fix | ||
Red Hat Enterprise Linux 8 | python39:3.9/scipy | Will not fix | ||
Red Hat Enterprise Linux 9 | python3.11-scipy | Will not fix | ||
Red Hat Enterprise Linux 9 | scipy | Will not fix | ||
Red Hat OpenShift Container Platform 4 | python-sortedcontainers | Not affected | ||
Red Hat Software Collections | rh-python38-scipy | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
7 High
CVSS3
Связанные уязвимости
** DISPUTED ** A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
A use-after-free issue was discovered in Py_FindObjects() function in ...
Уязвимость функции Py_FindObjects() библиотеки для языка программирования Python с открытым исходным кодом scipy, позволяющая нарушителю оказывать влияние на конфиденциальность, целостность и доступность системы
EPSS
7 High
CVSS3