Incorrect Comparison in Numpy - CVE-2021-34141

 

Incorrect Comparison in Numpy - CVE-2021-34141

Published: March 24, 2022


Vulnerability identifier: #VU61602
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34141
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incomplete string comparison in the numpy.core component in NumPy. A remote attacker can pass specific string objects to the library and perform a denial of service (DoS) attack.


Affected software

Numpy
IBM Watson Machine Learning Accelerator
Python for Scientific Computing
openEuler
Ubuntu
Oracle Communications Cloud Native Core Policy
Cloud Pak for Security (CP4S)
python2-numpy-f2py
python2-numpy
numpy-debugsource
numpy-debuginfo
numpy
python3-numpy
python3-numpy-f2py
python3-numpy (Ubuntu package)
watsonx.data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM InfoSphere Information Server

How to mitigate CVE-2021-34141

Install updates from vendor's website.

Numpy - update to 1.22.0
Python for Scientific Computing - update to 4.2.1
Cloud Pak for Security (CP4S) - update to 1.10.8.0
python2-numpy-f2py - update to 1.16.5-6
python2-numpy - update to 1.16.5-6
numpy-debugsource - update to 1.16.5-6
numpy-debuginfo - update to 1.16.5-6
numpy - update to 1.16.5-6
python3-numpy - update to 1.16.5-6
python3-numpy-f2py - update to 1.16.5-6
python3-numpy (Ubuntu package) - addressed in versions 1:1.17.4-5ubuntu3.1, 1:1.21.5-1ubuntu22.04.1, 1:1.21.5-1ubuntu22.10.1
watsonx.data - update to 2.0.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
IBM InfoSphere Information Server - update to 11.7.1.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5

External References

Related Security Bulletins