Safety vulnerability ID: 54297
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Scikit-learn 1.1.0rc1 includes a fix for CVE-2020-28975: svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array.
NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.
Latest version: 1.5.2
A set of python modules for machine learning and data mining
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application