CVE-2023-25399

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-25399
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25399.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-25399
Aliases
Related
Withdrawn
2024-05-13T22:13:32Z
Published
2023-07-05T17:15:09Z
Modified
2024-09-18T03:23:13.324778Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.

References

Affected packages

Debian:11 / scipy

Package

Name
scipy
Purl
pkg:deb/debian/scipy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.0-2
1.6.1-1
1.6.2-1
1.7.0-1
1.7.1-1
1.7.1-2
1.7.3-1
1.7.3-2
1.7.3-3~1exp1
1.8.0-1exp1
1.8.0-1exp2
1.8.1-1
1.8.1-2
1.8.1-3
1.8.1-4
1.8.1-5
1.8.1-6
1.8.1-7
1.8.1-8
1.8.1-9
1.8.1-10
1.8.1-11
1.8.1-12
1.8.1-13
1.8.1-14
1.8.1-15
1.8.1-16
1.8.1-17
1.8.1-18
1.8.1-19
1.8.1-20
1.8.1-21
1.8.1-22
1.10.0-1exp1
1.10.0-1exp2
1.10.0-1exp3
1.10.0-1exp4
1.10.0-1exp5
1.10.0-1exp6
1.10.0-2
1.10.0-3
1.10.0-4
1.10.0-5
1.10.0-6
1.10.0-7
1.10.0-8
1.10.0-9
1.10.0-10
1.10.0-11
1.10.0-12
1.10.1-1
1.10.1-2
1.10.1-3
1.10.1-4
1.10.1-5
1.10.1-6
1.10.1-7
1.10.1-8
1.10.1-9
1.10.1-10
1.11.1-1exp1
1.11.1-1exp2
1.11.4-1
1.11.4-2
1.11.4-3
1.11.4-4
1.11.4-5
1.11.4-6
1.11.4-7
1.11.4-8
1.11.4-9
1.11.4-10
1.12.0-1exp1
1.12.0-1exp2
1.12.0-1exp3
1.12.0-2
1.13.1-1exp1
1.13.1-1exp2
1.13.1-1exp3
1.13.1-1exp4
1.13.1-1exp5
1.13.1-1exp6
1.13.1-1exp7
1.13.1-1exp8
1.13.1-1exp9
1.13.1-1exp10
1.13.1-1exp11
1.13.1-1exp12
1.13.1-1exp13
1.13.1-1exp14
1.13.1-1exp15
1.13.1-2
1.13.1-3
1.13.1-4
1.13.1-5
1.14.0-1exp1
1.14.0-1exp2
1.14.0-1exp3
1.14.0-1exp4
1.14.0-1exp5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / scipy

Package

Name
scipy
Purl
pkg:deb/debian/scipy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / scipy

Package

Name
scipy
Purl
pkg:deb/debian/scipy?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}