HIGH
Google TensorFlow 1.7 and below is affected by: Buffer Overflow
Published Apr 23, 2019
8.7
HIGHCVSS 4.0
EPSS 0.74%
Description
Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local).
Affected products
No data.
- ≤ 1.7.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/advisories/GHSA-frxx-2m33-6wcr Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2019-226.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2019-233.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2019-208.yaml
- https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2018-003.md x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/tensorflow/tensorflow/commit/41335abb46f80ca644b5738550daef6136ba5476
- https://github.com/tensorflow/tensorflow/commit/8badd11d875a826bd318ed439909d5c47a7fb811
- https://nvd.nist.gov/vuln/detail/CVE-2018-8825
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 23, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2018
Link CVE-2018-8825
CISA Vulnrichment
GHSA-FRXX-2M33-6WCR Updated n/a