Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15211

Опубликовано: 25 сент. 2020
Источник: nvd
CVSS3: 4.8
CVSS2: 5.8
EPSS Низкий

Описание

In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices for the tensors, indexing into an array of tensors that is owned by the subgraph. This results in a pattern of double array indexing when trying to get the data of each tensor. However, some operators can have some tensors be optional. To handle this scenario, the flatbuffer model uses a negative -1 value as index for these tensors. This results in special casing during validation at model loading time. Unfortunately, this means that the -1 index is a valid tensor index for any operator, including those that don't expect optional inputs and including for output tensors. Thus, this allows writing and reading from outside the bounds of heap allocated arrays, although only at a specific offs

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:google:tensorflow:*:*:*:*:lite:*:*:*
Версия до 1.15.4 (исключая)
cpe:2.3:a:google:tensorflow:*:*:*:*:lite:*:*:*
Версия от 2.0.0 (включая) до 2.0.3 (исключая)
cpe:2.3:a:google:tensorflow:*:*:*:*:lite:*:*:*
Версия от 2.1.0 (включая) до 2.1.2 (исключая)
cpe:2.3:a:google:tensorflow:*:*:*:*:lite:*:*:*
Версия от 2.2.0 (включая) до 2.2.1 (исключая)
cpe:2.3:a:google:tensorflow:*:*:*:*:lite:*:*:*
Версия от 2.3.0 (включая) до 2.3.1 (исключая)
Конфигурация 2
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00344
Низкий

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.8
debian
больше 5 лет назад

In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3 ...

CVSS3: 4.8
github
больше 5 лет назад

Out of bounds access in tensorflow-lite

suse-cvrf
больше 5 лет назад

Security update for tensorflow2

EPSS

Процентиль: 56%
0.00344
Низкий

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-125