Логотип exploitDog
bind:CVE-2020-15211
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15211

Количество 4

Количество 4

nvd логотип

CVE-2020-15211

больше 5 лет назад

In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices for the tensors, indexing into an array of tensors that is owned by the subgraph. This results in a pattern of double array indexing when trying to get the data of each tensor. However, some operators can have some tensors be optional. To handle this scenario, the flatbuffer model uses a negative `-1` value as index for these tensors. This results in special casing during validation at model loading time. Unfortunately, this means that the `-1` index is a valid tensor index for any operator, including those that don't expect optional inputs and including for output tensors. Thus, this allows writing and reading from outside the bounds of heap allocated arrays, although only at a specific offs

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2020-15211

больше 5 лет назад

In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3 ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-cvpc-8phh-8f45

больше 5 лет назад

Out of bounds access in tensorflow-lite

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1766-1

больше 5 лет назад

Security update for tensorflow2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15211

In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices for the tensors, indexing into an array of tensors that is owned by the subgraph. This results in a pattern of double array indexing when trying to get the data of each tensor. However, some operators can have some tensors be optional. To handle this scenario, the flatbuffer model uses a negative `-1` value as index for these tensors. This results in special casing during validation at model loading time. Unfortunately, this means that the `-1` index is a valid tensor index for any operator, including those that don't expect optional inputs and including for output tensors. Thus, this allows writing and reading from outside the bounds of heap allocated arrays, although only at a specific offs

CVSS3: 4.8
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15211

In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3 ...

CVSS3: 4.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-cvpc-8phh-8f45

Out of bounds access in tensorflow-lite

CVSS3: 4.8
0%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1766-1

Security update for tensorflow2

больше 5 лет назад

Уязвимостей на страницу