An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
References
Link | Resource |
---|---|
https://github.com/numpy/numpy/issues/18993 | Exploit Issue Tracking Patch Third Party Advisory |
https://www.oracle.com/security-alerts/cpujul2022.html | Patch Third Party Advisory |
Information
Published : 2021-12-17 11:15
Updated : 2023-02-24 07:35
NVD link : CVE-2021-34141
Mitre link : CVE-2021-34141
JSON object : View
CWE
CWE-697
Incorrect Comparison
Products Affected
numpy
- numpy
oracle
- communications_cloud_native_core_policy