You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch releases for all versions between 1.15 and 2.3. We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
mend-for-github-combot
changed the title
CVE-2020-15210 (Medium) detected in multiple libraries
CVE-2020-15210 (Medium) detected in TensorIOTensorFlow-2.0.8, TensorFlowLite-1.13.1
Feb 10, 2021
mend-for-github-combot
changed the title
CVE-2020-15210 (Medium) detected in TensorIOTensorFlow-2.0.8, TensorFlowLite-1.13.1
CVE-2020-15210 (Medium) detected in multiple libraries
Feb 11, 2021
mend-for-github-combot
changed the title
CVE-2020-15210 (Medium) detected in multiple libraries
CVE-2020-15210 (Medium) detected in TensorIO-1.2.4, TensorIOTensorFlow-2.0.8
May 4, 2021
mend-for-github-combot
changed the title
CVE-2020-15210 (Medium) detected in TensorIO-1.2.4, TensorIOTensorFlow-2.0.8
CVE-2020-15210 (Medium) detected in TensorIOTensorFlow-2.0.8
May 6, 2021
CVE-2020-15210 - Medium Severity Vulnerability
Vulnerable Library - TensorIOTensorFlow-2.0.8
An unofficial build of TensorFlow for iOS used by TensorIO, supporting inference, evaluation, and training.
Library home page: https://storage.googleapis.com/tensorio-build/ios/release/2.0/xcodebuild/12C33/tag/2.0.8/pod/TensorIO-TensorFlow-2.0_8.tar.gz
Path to dependency file: tensorio-ios/TensorFlowExample/Podfile.lock
Path to vulnerable library: tensorio-ios/TensorFlowExample/Podfile.lock,tensorio-ios/SwiftTensorFlowExample/Podfile.lock
Dependency Hierarchy:
Found in HEAD commit: 9ca8c916de11c6aadffe21f686982bf1f761da36
Found in base branch: master
Vulnerability Details
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch releases for all versions between 1.15 and 2.3. We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
Publish Date: 2020-09-25
URL: CVE-2020-15210
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-x9j7-x98r-r4w2
Release Date: 2020-07-21
Fix Resolution: 1.15.4, 2.0.3, 2.1.2, 2.2.1, 2.3.1
The text was updated successfully, but these errors were encountered: