TensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad
CVE-2023-25664
7.5HIGH
What is CVE-2023-25664?
A heap buffer overflow vulnerability exists in the TAvgPoolGrad function of TensorFlow prior to version 2.12.0 and 2.11.1. This issue could potentially allow an attacker to execute arbitrary code or cause unexpected behavior within the application, compromising the security of systems utilizing this machine learning platform. Users are advised to upgrade to the patched versions to mitigate any risks associated with this vulnerability.
Affected Version(s)
tensorflow < 2.11.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved