Skip to content
TensorFlowGHSA-frxx-2m33-6wcr

Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow

High8.8CVE-2018-8825 · Published Apr 24, 2019 · updated Oct 28, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
tensorflow
PyPI
>= 1.5.0, < 1.7.11.7.1
Details and references

Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). Users passing a malformed or malicious version of a TFLite graph into TOCO will cause TOCO to crash or cause a buffer overflow, potentially allowing malicious code to be executed.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-119
Also known as
CVE-2018-8825, PYSEC-2019-208, PYSEC-2019-226, PYSEC-2019-233

More TensorFlow advisories

All TensorFlow
DateAdvisory
Apr 242019Null pointer dereference in TensorFlow leads to exploitation
CVE-2018-7576High6.5fixed in 1.6.0
Apr 302019Integer Overflow or Wraparound in Google TensorFlow
CVE-2018-7575Critical9.8fixed in 1.7.1
Apr 302019NULL Pointer Dereference in Google TensorFlow
CVE-2019-9635High6.5fixed in 1.12.1
Apr 302019Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
CVE-2018-10055High8.1fixed in 1.7.1
Apr 302019Improper Input Validation in Google TensorFlow
CVE-2018-7577High8.1fixed in 1.7.1
Dec 162019Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
CVE-2019-16778Low2.6fixed in 1.15.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.