CVE-2021-34141 PUBLISHED

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

EPSS 0.06% · 19.9th percentile

Risk Scores

EPSS Score
0.06%
19.9th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSnumpy1:1.21.5-1build2, 0, 1:1.19.5-1ubuntu2
Ubuntu:20.04:LTSnumpy1:1.17.3-0ubuntu2, 1:1.17.4-3ubuntu1, 1:1.17.4-3ubuntu2

Timeline

References

Open in Interactive Console →