Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.2.7+dfsg-2", "binary_name": "python-cvxopt-doc" }, { "binary_version": "1.2.7+dfsg-2", "binary_name": "python3-cvxopt" }, { "binary_version": "1.2.7+dfsg-2", "binary_name": "python3-cvxopt-dbgsym" } ] }