cve/2021/CVE-2021-41500.md
2024-05-25 21:48:12 +02:00

852 B

CVE-2021-41500

Description

Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

POC

Reference

No PoCs from references.

Github