CVE-2024-27319

MEDIUM4.4EPSS 0.09%

Onnx Out-of-bounds Read vulnerability

發布日:2024/2/23修改日:2026/2/4

描述

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.

受影響套件(2)

  • PyPI/onnxfrom 0, < 1.16.0
  • PyPI/onnxfrom 0, < 08a399ba75a805b7813ab8936b91d0e274b08287, < 08a399ba75a805b7813ab8936b91d0e274b08287 | from 0, < 1.16.0

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.4CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

參考連結(8)