Package | Installed | Affected | Info |
---|---|---|---|
numpy | 1.22.1 | <1.22.2 |
show Numpy 1.22.2 includes a fix for CVE-2021-41495: Null Pointer Dereference vulnerability exists in numpy.sort in NumPy in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place. NOTE2: The specs we include in this advisory differ from the publicly available on other sources. For example, the advisory posted by the NVD indicate that versions up to and including 1.19.0 are affected. However, research by Safety CLI Cybersecurity confirms that the vulnerability remained unaddressed until version 1.22.2. |
Package | Installed | Affected | Info |
---|---|---|---|
numpy | 1.22.1 | <1.22.2 |
show Numpy 1.22.2 includes a fix for CVE-2021-41495: Null Pointer Dereference vulnerability exists in numpy.sort in NumPy in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place. NOTE2: The specs we include in this advisory differ from the publicly available on other sources. For example, the advisory posted by the NVD indicate that versions up to and including 1.19.0 are affected. However, research by Safety CLI Cybersecurity confirms that the vulnerability remained unaddressed until version 1.22.2. |
https://pyup.io/repos/github/ericmjl/nxviz/python-3-shield.svg
[![Python 3](https://pyup.io/repos/github/ericmjl/nxviz/python-3-shield.svg)](https://pyup.io/repos/github/ericmjl/nxviz/)
.. image:: https://pyup.io/repos/github/ericmjl/nxviz/python-3-shield.svg :target: https://pyup.io/repos/github/ericmjl/nxviz/ :alt: Python 3
<a href="https://pyup.io/repos/github/ericmjl/nxviz/"><img src="https://pyup.io/repos/github/ericmjl/nxviz/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/ericmjl/nxviz/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/ericmjl/nxviz/
{<img src="https://pyup.io/repos/github/ericmjl/nxviz/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/ericmjl/nxviz/]
https://pyup.io/repos/github/ericmjl/nxviz/shield.svg
[![Updates](https://pyup.io/repos/github/ericmjl/nxviz/shield.svg)](https://pyup.io/repos/github/ericmjl/nxviz/)
.. image:: https://pyup.io/repos/github/ericmjl/nxviz/shield.svg :target: https://pyup.io/repos/github/ericmjl/nxviz/ :alt: Updates
<a href="https://pyup.io/repos/github/ericmjl/nxviz/"><img src="https://pyup.io/repos/github/ericmjl/nxviz/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/ericmjl/nxviz/shield.svg(Updates)!:https://pyup.io/repos/github/ericmjl/nxviz/
{<img src="https://pyup.io/repos/github/ericmjl/nxviz/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/ericmjl/nxviz/]