Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mw6v-crh8-8533

Опубликовано: 30 апр. 2019
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Integer Overflow or Wraparound in Google TensorFlow

Issue Description

Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent. The block size in meta file might contain a large int64 value which causes an integer overflow upon addition. Subsequent code using n as index may cause an out-of-bounds read.

Impact

A maliciously crafted meta checkpoint could be used to cause the TensorFlow process to perform an out of bounds read on in process memory.

Пакеты

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

>= 1.0.0, < 1.7.1

1.7.1

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

>= 1.0.0, < 1.7.1

1.7.1

EPSS

Процентиль: 39%
0.00176
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.8
nvd
почти 7 лет назад

Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.

CVSS3: 9.8
debian
почти 7 лет назад

Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow v ...

EPSS

Процентиль: 39%
0.00176
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-190