CVE-2018-7575
published 2019-04-24CVE-2018-7575: Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tensorflow | — | — |
| tensorflow | <= 1.7.0 | — | |
| intel | optimization_for_tensorflow | >= 0 < 1.7.1 | 1.7.1 |
| intel | optimization_for_tensorflow | >= 1.0.0 < 1.7.1 | 1.7.1 |
GHSA
Integer Overflow or Wraparound in Google TensorFlow
ghsa·2019-04-30
CVE-2018-7575 [CRITICAL] CWE-190 Integer Overflow or Wraparound in Google TensorFlow
Integer Overflow or Wraparound in Google TensorFlow
### Issue Description
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent. The block size in meta file might contain a large int64 value which causes an integer overflow upon addition. Subsequent code using n as index may cause an out-of-bounds read.
### Impact
A maliciously crafted meta checkpoint could be used to cause the TensorFlow process to perform an out of bounds read on in process memory.
OSV
Integer Overflow or Wraparound in Google TensorFlow
osv·2019-04-30
CVE-2018-7575 [CRITICAL] Integer Overflow or Wraparound in Google TensorFlow
Integer Overflow or Wraparound in Google TensorFlow
### Issue Description
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent. The block size in meta file might contain a large int64 value which causes an integer overflow upon addition. Subsequent code using n as index may cause an out-of-bounds read.
### Impact
A maliciously crafted meta checkpoint could be used to cause the TensorFlow process to perform an out of bounds read on in process memory.
OSV
CVE-2018-7575: Google TensorFlow 1
osv·2019-04-24
CVE-2018-7575 CVE-2018-7575: Google TensorFlow 1
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
Debian
CVE-2018-7575: tensorflow - Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerabili...
vendor_debian·2018·CVSS 9.8
CVE-2018-7575 [CRITICAL] CVE-2018-7575: tensorflow - Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerabili...
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
Scope: local
forky: resolved
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-24
Published