Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-25660

Опубликовано: 25 мар. 2023
Источник: debian

Описание

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a seg fault. A fix is included in TensorFlow version 2.12 and version 2.11.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tensorflownot-affectedpackage

Примечания

  • https://github.com/tensorflow/tensorflow/security/advisories/GHSA-qjqc-vqcf-5qvj

  • https://github.com/tensorflow/tensorflow/commit/6d423b8bcc9aa9f5554dc988c1c16d038b508df1 (v2.12.0-rc0)

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a seg fault. A fix is included in TensorFlow version 2.12 and version 2.11.1.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
github
почти 3 года назад

TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`