numpy is vulnerable to Heap Buffer Overflow
31
Low Risk
Affected versions of this package are vulnerable to a heap buffer overflow when calling numpy.strings.find on specific strings. The issue stems from an incorrect multiplication by sizeof(npy_ucs4), which leads to improper memory allocation and potential out-of-bounds access. This flaw can result in application crashes or could potentially be exploited to achieve arbitrary code execution.
You are affected if you are using a version that falls within the vulnerable range.
numpy is vulnerable to Heap Buffer Overflow in versions 2.2.0 - 2.2.5.
Upgrade the numpy library to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant