PT-2019-11147 · Google · Tensorflow

Publicado

2019-04-23

·

Atualizado

2019-04-25

·

CVE-2018-8825

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Google TensorFlow versions 1.7 and below
Description: The issue allows for the execution of arbitrary code locally due to a buffer overflow. This can occur when users pass a malformed or malicious version of a TFLite graph into TOCO, causing TOCO to crash or resulting in a buffer overflow, which could potentially allow malicious code to be executed.
Recommendations: For Google TensorFlow versions 1.7 and below, consider restricting the input to TOCO to prevent the execution of malicious code until a fix is available. As a temporary workaround, avoid using malformed or malicious TFLite graphs in TOCO. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-8825
GHSA-FRXX-2M33-6WCR
PYSEC-2019-208
PYSEC-2019-226
PYSEC-2019-233

Produtos afetados

Tensorflow