MEDIUM 5.3 PyPI
Incorrect Comparison in NumPy
GHSA-fpfv-jqm9-f5jm · CVE-2021-34141 · PYSEC-2021-855
Published · Modified
Description
Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific string objects.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-34141
- WEB https://github.com/numpy/numpy/issues/18993
- WEB https://github.com/numpy/numpy/issues/18993#issuecomment-1010735102
- ADVISORY https://github.com/advisories/GHSA-fpfv-jqm9-f5jm
- PACKAGE https://github.com/numpy/numpy
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/numpy/PYSEC-2021-855.yaml
- WEB https://www.oracle.com/security-alerts/cpujul2022.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes