Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-25399
HistoryJul 06, 2023 - 12:00 a.m.

CVE-2023-25399

2023-07-0600:00:00
ubuntu.com
ubuntu.com
14
cve-2023-25399
refcounting issue
scipy commit
memory leak
py_findobjects()
unix

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

DISPUTED A refcounting issue which leads to potential memory leak was
discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note:
This is disputed as a bug and not a vulnerability. SciPy is not designed to
be exposed to untrusted users or data directly.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchscipy< 1.3.3-3ubuntu0.1~esm1UNKNOWN
ubuntu22.04noarchscipy< 1.8.0-1exp2ubuntu1+esm1UNKNOWN
ubuntu22.10noarchscipy< 1.8.1-10ubuntu0.22.10.1UNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%