CVE-2017-12852 PUBLISHED

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

EPSS 0.81% · 74.1th percentile

Risk Scores

EPSS Score
0.81%
74.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSpython-numpy1:1.13.3-2ubuntu1, 0, 1:1.12.1-3.1ubuntu4
Ubuntu:16.04:LTSpython-numpy1:1.8.2-1ubuntu2, 1:1.8.2-1ubuntu3, 1:1.10.4-2ubuntu2

Timeline

References

Open in Interactive Console →