#VU34413 Out-of-bounds read in TensorFlow - CVE-2018-21233
Published: May 4, 2020 / Updated: August 8, 2020
TensorFlow
TensorFlow
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.