VYPR

PyPI package

cvxopt

pkg:pypi/cvxopt

Vulnerabilities (1)

  • CVE-2021-41500Dec 17, 2021
    affected < 1.2.7fixed 1.2.7

    Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.