PT-2017-12727 · Numpy+2 · Numpy+2

Bt123

·

Published

2017-08-15

·

Updated

2024-09-04

·

CVE-2017-12852

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Numpy versions 1.13.1 and earlier
Description The issue is related to missing input validation in the numpy.pad function. This can cause an infinite loop when an empty list or ndarray is used, potentially allowing attackers to conduct a Denial of Service (DoS) attack.
Recommendations For versions 1.13.1 and earlier, consider adding input validation to the numpy.pad function to prevent empty lists or ndarrays from causing an infinite loop. As a temporary workaround, restrict the use of the numpy.pad function with unvalidated input until a fix is available.

Exploit

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2852
CVE-2017-12852
GHSA-FRGW-FGH6-9G52
OPENSUSE-SU-2024:11243-1
OPENSUSE-SU-2024:13820-1
OPENSUSE-SU-2024:14311-1
PYSEC-2017-1
SUSE-RU-2017:3010-1
SUSE-SU-2022:3954-1
SUSE-SU-2022_3954-1

Affected Products

Alt Linux
Numpy
Suse