CVE-2021-41496: Buffer Overflow
Published Dec 17, 2021
·Updated
DISPUTED Buffer overflow in the arrayfrompyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally).
Affected Software
1 affected component
NumPy NumPy<1.19.0
Remediation
Patch Available
Event History
Dec 17, 2021
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
Description
Disputed
08:15 PM
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this buffer overflow issue?
The vulnerability ID for this buffer overflow issue is CVE-2021-41496.
2
What software is affected by this vulnerability?
The NumPy version prior to 1.19 is affected by this vulnerability.
3
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium with a CVSS score of 5.5.
4
What can an attacker do with this vulnerability?
An attacker could conduct a Denial of Service (DoS) attack by carefully constructing an array with negative values.
5
Has this vulnerability been disputed by the vendor?
Yes, this vulnerability has been disputed by the vendor.