Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-28975

Опубликовано: 21 нояб. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:scikit-learn:scikit-learn:*:*:*:*:*:*:*:*
Версия от 0.23.2 (включая) до 1.0.1 (исключая)

EPSS

Процентиль: 74%
0.00815
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.

CVSS3: 7.5
debian
около 5 лет назад

svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn ...

CVSS3: 7.5
github
больше 3 лет назад

scikit-learn Denial of Service

CVSS3: 7.5
fstec
около 5 лет назад

Уязвимость функции svm_predict_values (svm.cpp) библиотеки машинного обучения scikit-learn, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 74%
0.00815
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo