The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1:1.16.2-1ubuntu1", "binary_name": "python-numpy" }, { "binary_version": "1:1.16.2-1ubuntu1", "binary_name": "python-numpy-dbg" }, { "binary_version": "1:1.16.2-1ubuntu1", "binary_name": "python-numpy-doc" }, { "binary_version": "1:1.16.2-1ubuntu1", "binary_name": "python3-numpy" }, { "binary_version": "1:1.16.2-1ubuntu1", "binary_name": "python3-numpy-dbg" } ] }