Описание
In Tensorflow before version 2.3.1, the SparseCountSparseOutput implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the indices tensor has the same shape as the values one. The values in these tensors are always accessed in parallel. Thus, a shape mismatch can result in accesses outside the bounds of heap allocated buffers. The issue is patched in commit 3cbb917b4714766030b28eba9fb41bb97ce9ee02 and is released in TensorFlow version 2.3.1.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.3.0 (включая) до 2.3.1 (исключая)
cpe:2.3:a:google:tensorflow:*:*:*:*:-:*:*:*
EPSS
Процентиль: 38%
0.00169
Низкий
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-119
CWE-119
Связанные уязвимости
CVSS3: 5.4
debian
больше 5 лет назад
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` impl ...
EPSS
Процентиль: 38%
0.00169
Низкий
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-119
CWE-119