CVE-2018-7575
published 2019-04-24CVE-2018-7575: Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
PriorityP341critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.61%
45.5th percentile
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tensorflow | — | — |
| tensorflow | <= 1.7.0 | — | |
| intel | optimization_for_tensorflow | >= 0 < 1.7.1 | 1.7.1 |
| intel | optimization_for_tensorflow | >= 1.0.0 < 1.7.1 | 1.7.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Integer Overflow or Wraparound in Google TensorFlow
ghsa·2019-04-30
CVE-2018-7575 [CRITICAL] CWE-190 Integer Overflow or Wraparound in Google TensorFlow
Integer Overflow or Wraparound in Google TensorFlow
### Issue Description
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent. The block size in meta file might contain a large int64 value which causes an integer overflow upon addition. Subsequent code using n as index may cause an out-of-bounds read.
### Impact
A maliciously crafted meta checkpoint could be used to cause the TensorFlow process to perform an out of bounds read on in process memory.
OSV
Integer Overflow or Wraparound in Google TensorFlow
osv·2019-04-30
CVE-2018-7575 [CRITICAL] Integer Overflow or Wraparound in Google TensorFlow
Integer Overflow or Wraparound in Google TensorFlow
### Issue Description
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent. The block size in meta file might contain a large int64 value which causes an integer overflow upon addition. Subsequent code using n as index may cause an out-of-bounds read.
### Impact
A maliciously crafted meta checkpoint could be used to cause the TensorFlow process to perform an out of bounds read on in process memory.
OSV
CVE-2018-7575: Google TensorFlow 1
osv·2019-04-24
CVE-2018-7575 CVE-2018-7575: Google TensorFlow 1
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
Debian
CVE-2018-7575: tensorflow - Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerabili...
vendor_debian·2018·CVSS 9.8
CVE-2018-7575 [CRITICAL] CVE-2018-7575: tensorflow - Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerabili...
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
Scope: local
forky: resolved
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-24
Published