Lucene search

K
mageiaGentoo FoundationMGASA-2024-0078
HistoryMar 21, 2024 - 7:56 a.m.

Updated python-scipy packages fix security vulnerability

2024-03-2107:56:12
Gentoo Foundation
advisories.mageia.org
17
python
scipy
memory leak
security
vulnerability
unix

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. (CVE-2023-25399

OSVersionArchitecturePackageVersionFilename
Mageia9noarchpython-scipy< 1.9.1-2.1python-scipy-1.9.1-2.1.mga9

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%