Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.5 PyPI

Buffer Copy without Checking Size of Input in NumPy

GHSA-f7c7-j99h-c22f · CVE-2021-41496 · PYSEC-2021-857

Published · Modified

Description

Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values.

Ready to move

Start Securing

Free, no credit card | First findings in minutes