Input validation error in TensorFlow - CVE-2020-15203

 

Input validation error in TensorFlow - CVE-2020-15203

Published: September 25, 2020 / Updated: October 2, 2020


Vulnerability identifier: #VU47289
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15203
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker is able to trigger a format string vulnerability due to the way the internal format use in a `printf` call is constructed. This may result in segmentation fault. The issue is patched in commit 33be22c65d86256e6826666662e40dbdfe70ee83, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.


Affected software

TensorFlow

How to mitigate CVE-2020-15203

Install update from vendor's website.

TensorFlow - addressed in versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, 2.3.1

External References

Related Security Bulletins