—
PYSEC-2021-870
Quick fix
PYSEC-2021-870 — cvxopt: upgrade to the fixed version with the command below.
pip install --upgrade 'cvxopt>=1.2.7'Details
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
Are you affected?
Enter the version of the package you're using.