First published: Tue Apr 23 2019(Updated: )
Google TensorFlow 1.0.0 through 1.5.1 is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google TensorFlow | <=1.6.0 | |
pip/tensorflow-gpu | >=1.0.0<1.6.0 | 1.6.0 |
pip/tensorflow | >=1.0.0<1.6.0 | 1.6.0 |
https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2018-002.md
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7576 has a context-dependent severity due to the Null Pointer Dereference vulnerability in Google TensorFlow.
To fix CVE-2018-7576, upgrade your Google TensorFlow version to 1.6.0 or later.
Google TensorFlow versions from 1.0.0 through 1.6.0 are affected by CVE-2018-7576.
CVE-2018-7576 is characterized as a Null Pointer Dereference vulnerability.
CVE-2018-7576 is context-dependent, meaning it may only be exploitable under certain conditions.