Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-9641

dev-python/numpy-1.16.1 CVE-2021-34141 CVE-2021-41495 CVE-2021-41496 Vulnerabilitie

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Invalid
    • Icon: Normal Normal
    • None
    • None
    • make numpy autogened

      [

      { "id": "CVE-2021-34141", "is_known_exploited_vuln": false, "description": "An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is \"completely harmless.\"", "urls": [ "https://nvd.nist.gov/vuln/detail/CVE-2021-34141", "https://github.com/numpy/numpy/issues/18993" ] }

      ,

      { "id": "CVE-2021-41495", "is_known_exploited_vuln": false, "description": "** DISPUTED ** Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place.", "urls": [ "https://nvd.nist.gov/vuln/detail/CVE-2021-41495", "https://github.com/numpy/numpy/issues/19038" ] }

      ,

      { "id": "CVE-2021-41496", "is_known_exploited_vuln": false, "description": "** DISPUTED ** Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally).", "urls": [ "https://nvd.nist.gov/vuln/detail/CVE-2021-41496", "https://github.com/numpy/numpy/issues/19000" ] }

      ]

            alex2101 alex2101 [X] (Inactive)
            tczaude tczaude
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: