PT-2017-12727 · Numpy+2 · Numpy+2
Bt123
·
Published
2017-08-15
·
Updated
2024-09-04
·
CVE-2017-12852
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Numpy versions 1.13.1 and earlier
Description
The issue is related to missing input validation in the numpy.pad function. This can cause an infinite loop when an empty list or ndarray is used, potentially allowing attackers to conduct a Denial of Service (DoS) attack.
Recommendations
For versions 1.13.1 and earlier, consider adding input validation to the numpy.pad function to prevent empty lists or ndarrays from causing an infinite loop. As a temporary workaround, restrict the use of the numpy.pad function with unvalidated input until a fix is available.
Exploit
Fix
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Numpy
Suse