Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-5187

Опубликовано: 14 нояб. 2024
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

Описание отсутствует

EPSS

Процентиль: 80%
0.01357
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 1 года назад

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of system, personal, or application files, thus impacting the integrity and availability of the system. The issue arises from the function's handling of tar file extraction without performing security checks on the paths within the tar file, as demonstrated by the ability to overwrite the `/home/kali/.ssh/authorized_keys` file by specifying an absolute path in the malicious tar file.

CVSS3: 8.8
nvd
больше 1 года назад

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of system, personal, or application files, thus impacting the integrity and availability of the system. The issue arises from the function's handling of tar file extraction without performing security checks on the paths within the tar file, as demonstrated by the ability to overwrite the `/home/kali/.ssh/authorized_keys` file by specifying an absolute path in the malicious tar file.

CVSS3: 8.8
debian
больше 1 года назад

A vulnerability in the `download_model_with_test_data` function of the ...

CVSS3: 8.8
github
больше 1 года назад

onnx allows Arbitrary File Overwrite in download_model_with_test_data

CVSS3: 8.8
fstec
почти 2 года назад

Уязвимость функции download_model_with_test_data() библиотеки программного обеспечения для построения нейронных сетей глубокого обучения Open Neural Network Exchange (ONNX), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 80%
0.01357
Низкий

8.8 High

CVSS3