Логотип exploitDog
bind:CVE-2020-15208
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15208

Количество 4

Количество 4

nvd логотип

CVE-2020-15208

больше 5 лет назад

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can craft cases where this is larger than that of the second tensor. In turn, this would result in reads/writes outside of bounds since the interpreter will wrongly assume that there is enough data in both tensors. The issue is patched in commit 8ee24e7949a203d234489f9da2c5bf45a7d5157d, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2020-15208

больше 5 лет назад

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3 ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-mxjj-953w-2c2v

больше 5 лет назад

Data corruption in tensorflow-lite

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1766-1

больше 5 лет назад

Security update for tensorflow2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15208

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can craft cases where this is larger than that of the second tensor. In turn, this would result in reads/writes outside of bounds since the interpreter will wrongly assume that there is enough data in both tensors. The issue is patched in commit 8ee24e7949a203d234489f9da2c5bf45a7d5157d, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.

CVSS3: 7.4
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15208

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3 ...

CVSS3: 7.4
0%
Низкий
больше 5 лет назад
github логотип
GHSA-mxjj-953w-2c2v

Data corruption in tensorflow-lite

CVSS3: 7.4
0%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1766-1

Security update for tensorflow2

больше 5 лет назад

Уязвимостей на страницу