CVE Vulnerabilities

CVE-2021-34141

Incorrect Comparison

Published: Dec 17, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
2.2 LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is completely harmless.

Weakness

The product compares two entities in a security-relevant context, but the comparison is incorrect.

Affected Software

NameVendorStart VersionEnd Version
NumpyNumpy*1.22.0 (excluding)
NumpyUbuntuesm-infra/focal*
NumpyUbuntufocal*
NumpyUbuntuhirsute*
NumpyUbuntuimpish*
NumpyUbuntujammy*
NumpyUbuntukinetic*
NumpyUbuntutrusty*
NumpyUbuntuupstream*
NumpyUbuntuxenial*

Extended Description

This Pillar covers several possibilities:

References