GHSA-6p56-wp2h-9hxr

Suggest an improvement
Source
https://github.com/advisories/GHSA-6p56-wp2h-9hxr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-6p56-wp2h-9hxr/GHSA-6p56-wp2h-9hxr.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6p56-wp2h-9hxr
Aliases
Published
2022-01-07T00:09:39Z
Modified
2024-09-26T14:57:16.181200Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
NumPy Buffer Overflow (Disputed)
Details

A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArrayNewFromDescrint function of ctors.c when specifying arrays of large dimensions (over 32) from Python code, which could let a malicious user cause a Denial of Service.

NOTE: The vendor does not agree this is a vulnerability; In (very limited) circumstances a user may be able provoke the buffer overflow, the user is most likely already privileged to at least provoke denial of service by exhausting memory. Triggering this further requires the use of uncommon API (complicated structured dtypes), which is very unlikely to be available to an unprivileged user.

Database specific
{
    "nvd_published_at": "2021-12-17T19:15:00Z",
    "cwe_ids": [
        "CWE-120"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-01-04T20:52:47Z"
}
References

Affected packages

PyPI / numpy

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.9.0
Fixed
1.21

Affected versions

1.*

1.9.0
1.9.1
1.9.2
1.9.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.3
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.15.4
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.17.0
1.17.1
1.17.2
1.17.3
1.17.4
1.17.5
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.19.0
1.19.1
1.19.2
1.19.3
1.19.4
1.19.5
1.20.0
1.20.1
1.20.2
1.20.3