Junglewise Threat Intelligence

PYSEC-2019-38 - ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attacke

Severity: info · Published 2019-01-16

Technologies: numpy (PyPI). Vendors: PyPI.

Executive brief

** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

Affected products

  • PyPI numpy

Related threats