Описание
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can produce negative numbers, resulting in accessing out of bounds heap memory. This is unlikely to be exploitable and was detected and fixed internally in TensorFlow 1.15 and 2.0.
Ссылки
- Third Party Advisory
- Patch
- PatchThird Party Advisory
- Third Party Advisory
- Patch
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.0.0 (включая) до 1.15.0 (исключая)
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00336
Низкий
2.6 Low
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-122
CWE-681
Связанные уязвимости
CVSS3: 2.6
debian
около 6 лет назад
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSu ...
CVSS3: 2.6
github
около 6 лет назад
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
EPSS
Процентиль: 56%
0.00336
Низкий
2.6 Low
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-122
CWE-681