An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.17.4-5ubuntu3.1", "binary_name": "python-numpy-doc" }, { "binary_version": "1:1.17.4-5ubuntu3.1", "binary_name": "python3-numpy" }, { "binary_version": "1:1.17.4-5ubuntu3.1", "binary_name": "python3-numpy-dbg" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.21.5-1ubuntu22.04.1", "binary_name": "python-numpy-doc" }, { "binary_version": "1:1.21.5-1ubuntu22.04.1", "binary_name": "python3-numpy" }, { "binary_version": "1:1.21.5-1ubuntu22.04.1", "binary_name": "python3-numpy-dbgsym" } ] }