CVE-2023-29824

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-29824
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-29824.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-29824
Aliases
Related
Withdrawn
2023-07-11T00:00:00Z
Published
2023-07-06T21:15:09Z
Modified
2024-10-12T10:52:51.142949Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.

References

Affected packages

Debian:11 / scipy

Package

Name
scipy
Purl
pkg:deb/debian/scipy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.0-2
1.6.1-1
1.6.2-1
1.7.0-1
1.7.1-1
1.7.1-2
1.7.3-1
1.7.3-2
1.7.3-3~1exp1
1.8.0-1exp1
1.8.0-1exp2
1.8.1-1
1.8.1-2
1.8.1-3
1.8.1-4
1.8.1-5
1.8.1-6
1.8.1-7
1.8.1-8
1.8.1-9
1.8.1-10
1.8.1-11
1.8.1-12
1.8.1-13
1.8.1-14
1.8.1-15
1.8.1-16
1.8.1-17
1.8.1-18
1.8.1-19
1.8.1-20
1.8.1-21
1.8.1-22
1.10.0-1exp1
1.10.0-1exp2
1.10.0-1exp3
1.10.0-1exp4
1.10.0-1exp5
1.10.0-1exp6
1.10.0-2
1.10.0-3
1.10.0-4
1.10.0-5
1.10.0-6
1.10.0-7
1.10.0-8
1.10.0-9
1.10.0-10
1.10.0-11
1.10.0-12
1.10.1-1
1.10.1-2
1.10.1-3
1.10.1-4
1.10.1-5
1.10.1-6
1.10.1-7
1.10.1-8
1.10.1-9
1.10.1-10
1.11.1-1exp1
1.11.1-1exp2
1.11.4-1
1.11.4-2
1.11.4-3
1.11.4-4
1.11.4-5
1.11.4-6
1.11.4-7
1.11.4-8
1.11.4-9
1.11.4-10
1.12.0-1exp1
1.12.0-1exp2
1.12.0-1exp3
1.12.0-2
1.13.1-1exp1
1.13.1-1exp2
1.13.1-1exp3
1.13.1-1exp4
1.13.1-1exp5
1.13.1-1exp6
1.13.1-1exp7
1.13.1-1exp8
1.13.1-1exp9
1.13.1-1exp10
1.13.1-1exp11
1.13.1-1exp12
1.13.1-1exp13
1.13.1-1exp14
1.13.1-1exp15
1.13.1-2
1.13.1-3
1.13.1-4
1.13.1-5
1.14.0-1exp1
1.14.0-1exp2
1.14.0-1exp3
1.14.0-1exp4
1.14.0-1exp5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / scipy

Package

Name
scipy
Purl
pkg:deb/debian/scipy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / scipy

Package

Name
scipy
Purl
pkg:deb/debian/scipy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/scipy/scipy

Affected ranges

Type
GIT
Repo
https://github.com/scipy/scipy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0
v0.1.1
v0.1.2
v0.17pre
v0.4.3

v1.*

v1.8.0rc1
v1.8.0rc2
v1.8.0rc3
v1.8.0rc4