CVE-2021-41496 (High) detected in numpy-1.21.0-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl #280
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
v1.3.0
Issues and PRs related to version 1.3.0
CVE-2021-41496 - High Severity Vulnerability
Vulnerable Library - numpy-1.21.0-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl
NumPy is the fundamental package for array computing with Python.
Library home page: https://files.pythonhosted.org/packages/3f/03/c3526fb4e79a793498829ca570f2f868204ad9a8040afcd72d82a8f121db/numpy-1.21.0-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Path to dependency file: /benchmarks/perf-tool/requirements.txt
Path to vulnerable library: /benchmarks/perf-tool/requirements.txt
Dependency Hierarchy:
Found in HEAD commit: 2fb2ad116bc11bde3eab5695aed65392943c08ae
Found in base branch: main
Vulnerability Details
** DISPUTED ** Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally).
Publish Date: 2021-12-17
URL: CVE-2021-41496
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-41496
Release Date: 2021-12-17
Fix Resolution: autovizwidget - 0.12.7;numpy - 1.22.0rc1;numcodecs - 0.6.2;numpy-base - 1.11.3;numpy - 1.17.4
The text was updated successfully, but these errors were encountered: