Candidate: CVE-2021-41500 PublicDate: 2021-12-17 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41500 https://github.com/cvxopt/cvxopt/issues/193 Description: Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_cvxopt: upstream_cvxopt: released (1.2.7+dfsg-1) trusty/esm_cvxopt: needs-triage trusty_cvxopt: ignored (out of standard support) xenial_cvxopt: ignored (out of standard support) bionic_cvxopt: needs-triage focal_cvxopt: needs-triage hirsute_cvxopt: ignored (reached end-of-life) impish_cvxopt: needs-triage jammy_cvxopt: not-affected (1.2.7+dfsg-2) devel_cvxopt: not-affected (1.2.7+dfsg-2)