Описание
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected::Forward, MatrixDotVector in src/lstm/weightmatrix.cpp writes w.dim1() results into temp_line, which is sized from no_, and reads w.dim2() minus one inputs from curr_input, which is sized from ni_. A crafted .traineddata NT_SOFTMAX layer can therefore use inconsistent dimensions to cause a heap out-of-bounds write and read on the default LSTM engine, resulting in heap corruption, a crash, information disclosure, or potentially controlled corruption. No fixed release is available as of this review.
A flaw was found in Tesseract. The FullyConnected::DeSerialize function does not properly validate the dimensions of deserialized layers against the weight-matrix dimensions. This vulnerability allows a remote attacker to provide a specially crafted .traineddata file, leading to a heap out-of-bounds write and read during the FullyConnected::Forward operation. Successful exploitation can result in heap corruption, application crashes, or information disclosure.
Меры по смягчению последствий
To mitigate this issue, ensure that applications utilizing Tesseract only process .traineddata files from trusted and verified sources. Avoid processing .traineddata files obtained from untrusted or external origins.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | tesseract | Affected | ||
| Red Hat Enterprise Linux 8 | tesseract | Affected | ||
| Red Hat Enterprise Linux 9 | tesseract | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
(Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected::Forward, MatrixDotVector in src/lstm/weightmatrix.cpp writes w.dim1() results into temp_line, which is sized from no_, and reads w.dim2() minus one inputs from curr_input, which is sized from ni_. A crafted .traineddata NT_SOFTMAX layer can therefore use inconsistent dimensions to cause a heap out-of-bounds write and read on the default LSTM engine, resulting in heap corruption, a crash, information disclosure, or potentially controlled corruption. No fixed release is available as of this review.
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...
EPSS
7.8 High
CVSS3