Логотип exploitDog
bind:CVE-2021-29589
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-29589

Количество 3

Количество 3

nvd логотип

CVE-2021-29589

больше 4 лет назад

TensorFlow is an end-to-end open source platform for machine learning. The reference implementation of the `GatherNd` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c00e0179cda284e7e7/tensorflow/lite/kernels/internal/reference/reference_ops.h#L966). An attacker can craft a model such that `params` input would be an empty tensor. In turn, `params_shape.Dims(.)` would be zero, in at least one dimension. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.

CVSS3: 2.5
EPSS: Низкий
debian логотип

CVE-2021-29589

больше 4 лет назад

TensorFlow is an end-to-end open source platform for machine learning. ...

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-3w67-q784-6w7c

больше 4 лет назад

Division by zero in TFLite's implementation of `GatherNd`

CVSS3: 2.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-29589

TensorFlow is an end-to-end open source platform for machine learning. The reference implementation of the `GatherNd` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c00e0179cda284e7e7/tensorflow/lite/kernels/internal/reference/reference_ops.h#L966). An attacker can craft a model such that `params` input would be an empty tensor. In turn, `params_shape.Dims(.)` would be zero, in at least one dimension. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-29589

TensorFlow is an end-to-end open source platform for machine learning. ...

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3w67-q784-6w7c

Division by zero in TFLite's implementation of `GatherNd`

CVSS3: 2.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу