{"id":"PYSEC-2023-114","details":"** DISPUTED ** A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.","aliases":["CVE-2023-29824"],"modified":"2024-05-03T10:41:29.137159Z","published":"2023-07-06T21:15:00Z","references":[{"type":"REPORT","url":"https://github.com/scipy/scipy/issues/14713"},{"type":"WEB","url":"http://www.square16.org/achievement/cve-2023-29824/"},{"type":"FIX","url":"https://github.com/scipy/scipy/pull/15013"},{"type":"REPORT","url":"https://github.com/scipy/scipy/issues/14713#issuecomment-1629468565"}],"affected":[{"package":{"name":"scipy","ecosystem":"PyPI","purl":"pkg:pypi/scipy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0"}]}],"versions":["0.10.0","0.10.1","0.11.0","0.12.0","0.12.1","0.13.0","0.13.1","0.13.2","0.13.3","0.14.0","0.14.1","0.15.0","0.15.1","0.16.0","0.16.1","0.17.0","0.17.1","0.18.0","0.18.1","0.19.0","0.19.1","0.4.4","0.5.2","0.6.0","0.7.0","0.7.2","0.8.0","0.9.0","1.0.0","1.0.1","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.1","1.3.2","1.3.3","1.4.0","1.4.1","1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.6.0","1.6.1","1.6.2","1.6.3","1.7.0","1.7.1","1.7.2","1.7.3","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/scipy/PYSEC-2023-114.yaml"}}],"schema_version":"1.7.3"}