Incorrect Comparison in Numpy - CVE-2021-34141
Published: March 24, 2022
Vulnerability identifier: #VU61602
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34141
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incomplete string comparison in the numpy.core component in NumPy. A remote attacker can pass specific string objects to the library and perform a denial of service (DoS) attack.
Affected software
Numpy
IBM Watson Machine Learning Accelerator
Python for Scientific Computing
openEuler
Ubuntu
Oracle Communications Cloud Native Core Policy
Cloud Pak for Security (CP4S)
python2-numpy-f2py
python2-numpy
numpy-debugsource
numpy-debuginfo
numpy
python3-numpy
python3-numpy-f2py
python3-numpy (Ubuntu package)
watsonx.data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM InfoSphere Information Server
IBM Watson Machine Learning Accelerator
Python for Scientific Computing
openEuler
Ubuntu
Oracle Communications Cloud Native Core Policy
Cloud Pak for Security (CP4S)
python2-numpy-f2py
python2-numpy
numpy-debugsource
numpy-debuginfo
numpy
python3-numpy
python3-numpy-f2py
python3-numpy (Ubuntu package)
watsonx.data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM InfoSphere Information Server
How to mitigate CVE-2021-34141
Install updates from vendor's website.
Numpy - update to 1.22.0
Python for Scientific Computing - update to 4.2.1
Cloud Pak for Security (CP4S) - update to 1.10.8.0
python2-numpy-f2py - update to 1.16.5-6
python2-numpy - update to 1.16.5-6
numpy-debugsource - update to 1.16.5-6
numpy-debuginfo - update to 1.16.5-6
numpy - update to 1.16.5-6
python3-numpy - update to 1.16.5-6
python3-numpy-f2py - update to 1.16.5-6
python3-numpy (Ubuntu package) - addressed in versions 1:1.17.4-5ubuntu3.1, 1:1.21.5-1ubuntu22.04.1, 1:1.21.5-1ubuntu22.10.1
watsonx.data - update to 2.0.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
IBM InfoSphere Information Server - update to 11.7.1.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
Python for Scientific Computing - update to 4.2.1
Cloud Pak for Security (CP4S) - update to 1.10.8.0
python2-numpy-f2py - update to 1.16.5-6
python2-numpy - update to 1.16.5-6
numpy-debugsource - update to 1.16.5-6
numpy-debuginfo - update to 1.16.5-6
numpy - update to 1.16.5-6
python3-numpy - update to 1.16.5-6
python3-numpy-f2py - update to 1.16.5-6
python3-numpy (Ubuntu package) - addressed in versions 1:1.17.4-5ubuntu3.1, 1:1.21.5-1ubuntu22.04.1, 1:1.21.5-1ubuntu22.10.1
watsonx.data - update to 2.0.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
IBM InfoSphere Information Server - update to 11.7.1.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
External References
Related Security Bulletins
- Multiple vulnerabilities in Numpy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Denial of service in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Ubuntu update for numpy
- Incorrect comparison in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Watson Machine Learning Accelerator on Cloud Pak for Data
- openEuler update for numpy
- Splunk Python for Scientific Computing update for third-party packages
- IBM watsonx.data update for Python