Safety vulnerability ID: 53854
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25668: Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96
Latest version: 2.18.0
TensorFlow is an open source machine learning framework for everyone.
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1. See CVE-2023-25668.
MISC:https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaae35eccb: https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaae35eccb
MISC:https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96: https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application