Segfault in paddle.nextafter
CVE-2023-52302

4.7MEDIUM

Key Information:

Vendor
CVE Published:
3 January 2024

What is CVE-2023-52302?

The PaddlePaddle software framework contains a null pointer dereference vulnerability located within the 'paddle.nextafter' function. This flaw exists in the versions prior to 2.6.0 and can cause the system to experience runtime crashes, leading to denial of service for applications relying on the framework. It is crucial for developers and system administrators using these vulnerable versions to take immediate action to mitigate potential impacts on their systems.

Affected Version(s)

PaddlePaddle 0 < 2.6.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.