CVE-2021-34141Incorrect Comparison in Numpy

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 80.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateDec 7

Description

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages9 packages

NVDnumpy/numpy< 1.22.0
PyPInumpy/numpy1.9.01.10.0+1
Ubuntunumpy/numpy< 1:1.17.4-5ubuntu3.1+1
debiandebian/numpy

Patches

🔴Vulnerability Details

5
OSV
numpy vulnerabilities2022-12-07
GHSA
Incorrect Comparison in NumPy2021-12-18
OSV
Incorrect Comparison in NumPy2021-12-18
OSV
CVE-2021-34141: An incomplete string comparison in the numpy2021-12-17
OSV
CVE-2021-34141: Incomplete string comparison in the numpy2021-12-17

📋Vendor Advisories

5
Ubuntu
NumPy vulnerabilities2022-12-07
Oracle
Oracle Oracle Communications Risk Matrix: Policy (NumPy) — CVE-2021-341412022-07-15
Microsoft
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor stat2021-12-14
Red Hat
numpy: incomplete string comparison in the numpy.core component2021-05-11
Debian
CVE-2021-34141: numpy - An incomplete string comparison in the numpy.core component in NumPy before 1.22...2021

📄Research Papers

1
arXiv
Threat Assessment in Machine Learning based Systems2022-06-30
CVE-2021-34141 — Incorrect Comparison in Numpy | cvebase