A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
References
Link | Resource |
---|---|
http://www.square16.org/achievement/cve-2023-25399/ | Third Party Advisory |
https://github.com/scipy/scipy/issues/16235 | Exploit Issue Tracking Patch Vendor Advisory |
https://github.com/scipy/scipy/issues/16235#issuecomment-1625361328 | |
https://github.com/scipy/scipy/pull/16397 | Patch |
http://www.square16.org/achievement/cve-2023-25399/ | Third Party Advisory |
https://github.com/scipy/scipy/issues/16235 | Exploit Issue Tracking Patch Vendor Advisory |
https://github.com/scipy/scipy/issues/16235#issuecomment-1625361328 | |
https://github.com/scipy/scipy/pull/16397 | Patch |
Configurations
History
21 Nov 2024, 07:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.square16.org/achievement/cve-2023-25399/ - Third Party Advisory | |
References | () https://github.com/scipy/scipy/issues/16235 - Exploit, Issue Tracking, Patch, Vendor Advisory | |
References | () https://github.com/scipy/scipy/issues/16235#issuecomment-1625361328 - | |
References | () https://github.com/scipy/scipy/pull/16397 - Patch |
03 Jul 2024, 01:39
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-401 |
14 May 2024, 12:32
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | (en) A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly. |
11 Jul 2023, 19:14
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
References | (MISC) https://github.com/scipy/scipy/pull/16397 - Patch | |
References | (MISC) http://www.square16.org/achievement/cve-2023-25399/ - Third Party Advisory | |
References | (MISC) https://github.com/scipy/scipy/issues/16235 - Exploit, Issue Tracking, Patch, Vendor Advisory | |
First Time |
Scipy
Scipy scipy |
|
CPE | cpe:2.3:a:scipy:scipy:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-Other |
05 Jul 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-05 17:15
Updated : 2024-11-21 07:49
NVD link : CVE-2023-25399
Mitre link : CVE-2023-25399
CVE.ORG link : CVE-2023-25399
JSON object : View
Products Affected
scipy
- scipy
CWE