CVE-2018-8825: Buffer Overflow
Published Apr 23, 2019
·Updated
Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local).
Affected Software
3 affected componentsFixes available
pip/tensorflow-gpu>=1.5.0<1.7.1
1.7.1
pip/tensorflow>=1.5.0<1.7.1
1.7.1
Google TensorFlow<=1.7.0
Remediation
Event History
Apr 23, 2019
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
Description
Apr 24, 2019
Advisory Published
04:11 PM
Frequently Asked Questions
1
What is the severity of CVE-2018-8825?
The severity of CVE-2018-8825 is critical due to the potential for arbitrary code execution.
2
How do I fix CVE-2018-8825?
To fix CVE-2018-8825, upgrade to TensorFlow version 1.7.1 or later.
3
Which versions of TensorFlow are affected by CVE-2018-8825?
CVE-2018-8825 affects Google TensorFlow versions 1.7.0 and below.
4
What type of vulnerability is CVE-2018-8825?
CVE-2018-8825 is a buffer overflow vulnerability.
5
Can CVE-2018-8825 be exploited remotely?
CVE-2018-8825 typically requires local access to exploit, as it targets local executions.