The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.
References
Link | Resource |
---|---|
https://github.com/BT123/testcasesForMyRequest/tree/master/CVE-2017-12852 | |
https://github.com/numpy/numpy/issues/9560#issuecomment-322395292 | Exploit Third Party Advisory |
https://github.com/BT123/testcasesForMyRequest/tree/master/CVE-2017-12852 | |
https://github.com/numpy/numpy/issues/9560#issuecomment-322395292 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 03:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/BT123/testcasesForMyRequest/tree/master/CVE-2017-12852 - | |
References | () https://github.com/numpy/numpy/issues/9560#issuecomment-322395292 - Exploit, Third Party Advisory |
Information
Published : 2017-08-15 16:29
Updated : 2024-11-21 03:10
NVD link : CVE-2017-12852
Mitre link : CVE-2017-12852
CVE.ORG link : CVE-2017-12852
JSON object : View
Products Affected
numpy
- numpy
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')