CVE-2017-12852

high
Published 2017-08-15 · Modified 2023-11-08
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
5.0
VIR risk
7.5

Description

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-12852.html

OS impact

OSVersionStatusFixed in
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPInumpy<1.13.31.13.3

Application impact

VendorProductVersionsFixed
numpynumpy{"endIncluding":"1.13.1"}

References

CWEs

CWE-835

Verify integrity in audit chain (admin only). AS-IS.