CVE-2023-25662

CWE-190Integer Overflow6 documents6 sources
Severity
7.5HIGH
EPSS
0.2%
top 64.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
Latest updateMar 24
PublishedMar 25

Description

TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

PyPItensorflow< 2.11.1
PyPItensorflow-cpu< 2.11.1
PyPItensorflow-gpu< 2.11.1
NVDgoogle/tensorflow< 2.12.0
CVEListV5tensorflow/tensorflow< 2.11.1

Patches

🔴Vulnerability Details

3
OSV
TensorFlow vulnerable to integer overflow in EditDistance2023-03-24
GHSA
TensorFlow vulnerable to integer overflow in EditDistance2023-03-24
CVEList
TensorFlow vulnerable to integer overflow in EditDistance2023-03-24

📋Vendor Advisories

2
Microsoft
TensorFlow vulnerable to integer overflow in EditDistance2023-03-14
Debian
CVE-2023-25662: tensorflow - TensorFlow is an open source platform for machine learning. Versions prior to 2....2023
CVE-2023-25662 (HIGH CVSS 7.5) | TensorFlow is an open source platfo | cvebase.io