First published: Tue Nov 05 2019(Updated: )
The numpy packages provide NumPY. NumPY is an extension to the Python programming language, which adds support for large, multi-dimensional arrays and matrices, and a library of mathematical functions that operate on such arrays.<br>Security Fix(es):<br><li> numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution (CVE-2019-6446)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/numpy | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/numpy-debugsource | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy-debuginfo | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy-f2py | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/numpy-debugsource | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy-debuginfo | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy-f2py | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/numpy-debugsource | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy-debuginfo | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/python3-numpy-f2py | <1.14.3-9.el8 | 1.14.3-9.el8 |
redhat/numpy-debugsource | <1.14.3-9.el8.aa | 1.14.3-9.el8.aa |
redhat/python3-numpy | <1.14.3-9.el8.aa | 1.14.3-9.el8.aa |
redhat/python3-numpy-debuginfo | <1.14.3-9.el8.aa | 1.14.3-9.el8.aa |
redhat/python3-numpy-f2py | <1.14.3-9.el8.aa | 1.14.3-9.el8.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:3704 is classified as important.
To fix RHSA-2019:3704, update the affected numpy packages to version 1.14.3-9.el8 or higher.
The affected packages include numpy, python3-numpy, and their debug sources.
RHSA-2019:3704 addresses vulnerabilities related to crafted serialized data processing in numpy.
Yes, applying the fix for RHSA-2019:3704 is important to maintain system security and integrity.