PT-2023-9417 · Scipy+6 · Scipy+6

Snape3058

·

Published

2023-07-06

·

Updated

2024-12-10

·

CVE-2023-29824

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SciPy versions prior to 1.8.0
Description A use-after-free issue was discovered in the Py FindObjects() function. The vendor and discoverer indicate that this is not a security issue. The issue is related to the use of memory after it has been freed, which could potentially allow a remote attacker to impact the confidentiality, integrity, and availability of the system.
Recommendations For SciPy versions prior to 1.8.0, update to version 1.8.0 or later to resolve the issue. As a temporary workaround, consider disabling the Py FindObjects() function until a patch is available. However, since the vendor and discoverer indicate that this is not a security issue, the primary recommendation is to update to the latest version.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8424
ALT-PU-2024-16624
ALT-PU-2024-9087
BDU:2024-07432
CVE-2023-29824
GHSA-JRFM-2H82-XG28
OPENSUSE-SU-2023_2970-1
PYSEC-2023-114
RHSA-2023:5009
SUSE-SU-2023:2970-1
SUSE-SU-2023:3272-1
USN-6226-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Scipy
Suse
Ubuntu