* DISPUTED * Buffer overflow in the arrayfrompyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally).
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.17.4-5ubuntu3.1", "binary_name": "python-numpy-doc" }, { "binary_version": "1:1.17.4-5ubuntu3.1", "binary_name": "python3-numpy" }, { "binary_version": "1:1.17.4-5ubuntu3.1", "binary_name": "python3-numpy-dbg" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.21.5-1ubuntu22.04.1", "binary_name": "python-numpy-doc" }, { "binary_version": "1:1.21.5-1ubuntu22.04.1", "binary_name": "python3-numpy" }, { "binary_version": "1:1.21.5-1ubuntu22.04.1", "binary_name": "python3-numpy-dbgsym" } ] }