PT-2017-12727 · Numpy+2 · Numpy+2
Bt123
·
Publicado
2017-08-15
·
Atualizado
2024-09-04
·
CVE-2017-12852
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Numpy versions 1.13.1 and earlier
Description
The issue is related to missing input validation in the numpy.pad function. This can cause an infinite loop when an empty list or ndarray is used, potentially allowing attackers to conduct a Denial of Service (DoS) attack.
Recommendations
For versions 1.13.1 and earlier, consider adding input validation to the numpy.pad function to prevent empty lists or ndarrays from causing an infinite loop. As a temporary workaround, restrict the use of the numpy.pad function with unvalidated input until a fix is available.
Exploit
Correção
DoS
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Numpy
Suse