Логотип exploitDog
bind:CVE-2022-29208
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-29208

Количество 3

Количество 3

nvd логотип

CVE-2022-29208

больше 3 лет назад

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based denial of service. In multiple places throughout the code, one may compute an index for a write operation. However, the existing validation only checks against the upper bound of the array. Hence, it is possible to write before the array by massaging the input to generate negative values for `loc`. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-29208

больше 3 лет назад

TensorFlow is an open source platform for machine learning. Prior to v ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2r2f-g8mw-9gvr

больше 3 лет назад

Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-29208

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based denial of service. In multiple places throughout the code, one may compute an index for a write operation. However, the existing validation only checks against the upper bound of the array. Hence, it is possible to write before the array by massaging the input to generate negative values for `loc`. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-29208

TensorFlow is an open source platform for machine learning. Prior to v ...

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r2f-g8mw-9gvr

Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow

CVSS3: 7.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу