Логотип exploitDog
bind:CVE-2021-41208
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-41208

Количество 3

Количество 3

nvd логотип

CVE-2021-41208

больше 4 лет назад

TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of service (via dereferencing `nullptr`s or via `CHECK`-failures) as well as abuse undefined behavior (binding references to `nullptr`s). An attacker can also read and write from heap buffers, depending on the API that gets used and the arguments that are passed to the call. Given that the boosted trees implementation in TensorFlow is unmaintained, it is recommend to no longer use these APIs. We will deprecate TensorFlow's boosted trees APIs in subsequent releases. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-41208

больше 4 лет назад

TensorFlow is an open source platform for machine learning. In affecte ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-57wx-m983-2f88

около 4 лет назад

Incomplete validation in boosted trees code

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-41208

TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of service (via dereferencing `nullptr`s or via `CHECK`-failures) as well as abuse undefined behavior (binding references to `nullptr`s). An attacker can also read and write from heap buffers, depending on the API that gets used and the arguments that are passed to the call. Given that the boosted trees implementation in TensorFlow is unmaintained, it is recommend to no longer use these APIs. We will deprecate TensorFlow's boosted trees APIs in subsequent releases. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-41208

TensorFlow is an open source platform for machine learning. In affecte ...

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-57wx-m983-2f88

Incomplete validation in boosted trees code

CVSS3: 9.3
0%
Низкий
около 4 лет назад

Уязвимостей на страницу