First published: Thu Jul 06 2023(Updated: )
** DISPUTED ** A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/scipy | <1.3.3-3ubuntu0.1~ | 1.3.3-3ubuntu0.1~ |
debian/scipy | <=1.6.0-2 | 1.10.1-2 1.10.1-10 |
pip/scipy | <1.8.0 | 1.8.0 |
SciPy | <1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-29824 is disputed, as both the vendor and the discoverer indicate that it is not a security issue.
To fix CVE-2023-29824, upgrade to SciPy version 1.8.0 or later.
CVE-2023-29824 affects SciPy versions prior to 1.8.0.
CVE-2023-29824 is considered not to be a confirmed security vulnerability according to the vendor and discoverer.
CVE-2023-29824 describes a use-after-free issue in the Py_FindObjects() function.