cbcvebase.
CVE-2018-21233
published 2020-05-04

CVE-2018-21233: TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs…

PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.48%
38.6th percentile
TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.

Affected

4 ranges
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow< 1.7.01.7.0
inteloptimization_for_tensorflow>= 0 < 1.7.01.7.0
inteloptimization_for_tensorflow>= 0 < 49f73c55d56edffebde4bca4a407ad69c1cae43349f73c55d56edffebde4bca4a407ad69c1cae433

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.