CVE-2022-23584
Use after free in `DecodePng` in Tensorflow
7.6
HIGH
CVSS 3.1
EPSS 0.73%
描述
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::CommonFreeDecode(&decode)` gets called, the values of `decode.width` and `decode.height` are in an unspecified state. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
如何修補 CVE-2022-23584
要修補 CVE-2022-23584,請將受影響套件升級到下列已修補版本。
- —升級至 2.5.3 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 e746adbfcfee15e9cfdb391ff746c765b99bdf9b 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 e746adbfcfee15e9cfdb391ff746c765b99bdf9b 或更新版本
CVE-2022-23584 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(7)
- from 0, < 2.5.3, >= 2.6.0, < 2.6.3, >= 2.7.0, < 2.7.1
- from 0, < 2.5.3
- from 0, < 2.5.3, >= 2.6.0, < 2.6.3, >= 2.7.0, < 2.7.1
- from 0, < 2.5.3
- from 0, < e746adbfcfee15e9cfdb391ff746c765b99bdf9b | from 0, < 2.5.3, >= 2.6.0, < 2.6.3
- from 0, < 2.5.3
- from 0, < e746adbfcfee15e9cfdb391ff746c765b99bdf9b | from 0, < 2.5.3, >= 2.6.0, < 2.6.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |