CVE-2021-34141
⚪ Do wiadomości
Niekompletne porównanie łańcuchów w NumPy umożliwia atakującym niepoprawne kopiowanie obiektów.
CVSS
5.3
EPSS
1.6%
Exploit
poc
Vendor
numpy
Opis źródłowy (NVD)
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.6% |
| Opublikowano (NVD) | 2021-12-17 19:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:35 UTC |
Referencje
- https://github.com/numpy/numpy/issues/18993 ([email protected]) [Exploit, Issue Tracking, Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2022.html ([email protected]) [Patch, Third Party Advisory]