MEDIUM 6.5 PyPI
Null pointer dereference in TensorFlow leads to exploitation
GHSA-jfq2-rj7f-9gvf · CVE-2018-7576 · PYSEC-2019-206 · PYSEC-2019-224 · PYSEC-2019-231
Published · Modified
Description
Google TensorFlow 1.0.0 through 1.5.1 is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2018-7576
- WEB https://github.com/tensorflow/tensorflow/commit/c48431588e7cf8aff61d4c299231e3e925144df8
- ADVISORY https://github.com/advisories/GHSA-jfq2-rj7f-9gvf
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2019-224.yaml
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2019-231.yaml
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2019-206.yaml
- PACKAGE https://github.com/tensorflow/tensorflow
- WEB https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2018-002.md
Ready to move
Start Securing
Free, no credit card | First findings in minutes