CVE-2018-7577
published 2019-04-24CVE-2018-7577: Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process…
PriorityP429high8.1CVSS 3.0
AVNACLPRNUIRSUCHINAH
EPSS
0.43%
34.9th percentile
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tensorflow | — | — |
| snappy | — | — | |
| tensorflow | < 1.7.1 | 1.7.1 | |
| intel | optimization_for_tensorflow | >= 0 < 1.7.1 | 1.7.1 |
| intel | optimization_for_tensorflow | >= 1.1.0 < 1.7.1 | 1.7.1 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Google TensorFlow
osv·2019-04-30
CVE-2018-7577 [HIGH] Improper Input Validation in Google TensorFlow
Improper Input Validation in Google TensorFlow
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
GHSA
Improper Input Validation in Google TensorFlow
ghsa·2019-04-30
CVE-2018-7577 [HIGH] CWE-20 Improper Input Validation in Google TensorFlow
Improper Input Validation in Google TensorFlow
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
OSV
CVE-2018-7577: Memcpy parameter overlap in Google Snappy library 1
osv·2019-04-24
CVE-2018-7577 CVE-2018-7577: Memcpy parameter overlap in Google Snappy library 1
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
Debian
CVE-2018-7577: tensorflow - Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google Tenso...
vendor_debian·2018·CVSS 8.1
CVE-2018-7577 [HIGH] CVE-2018-7577: tensorflow - Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google Tenso...
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
Scope: local
forky: resolved
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-24
Published