The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.
{ "binaries": [ { "binary_name": "python-numpy", "binary_version": "1:1.11.0-1ubuntu1" }, { "binary_name": "python3-numpy", "binary_version": "1:1.11.0-1ubuntu1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-12852.json"
{ "binaries": [ { "binary_name": "python-numpy", "binary_version": "1:1.13.3-2ubuntu1" }, { "binary_name": "python3-numpy", "binary_version": "1:1.13.3-2ubuntu1" } ] }