FPE in paddle.nanmedian
CVE-2023-38674

4.7MEDIUM

Key Information:

Vendor
CVE Published:
3 January 2024

What is CVE-2023-38674?

A vulnerability exists in the PaddlePaddle framework that affects the paddle.nanmedian function. Versions prior to 2.6.0 are susceptible to this flaw, which can result in unexpected runtime crashes and can lead to a denial of service. Organizations utilizing affected versions should consider implementing appropriate mitigations or upgrades to ensure system stability and security.

Affected Version(s)

PaddlePaddle 0 < 2.6.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.