5
CVSSv2

CVE-2017-12852

Published: 15/08/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow malicious users to cause a DoS attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

numpy numpy

Vendor Advisories

Debian Bug report logs - #872407 python-numpy: CVE-2017-12852 Package: src:python-numpy; Maintainer for src:python-numpy is Sandro Tosi <morph@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 17 Aug 2017 07:09:02 UTC Severity: normal Tags: security, upstream Found in version python-numpy ...
The numpypad function in Numpy 1131 and older versions is missing input validation An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack ...