CVE-2019-10844: Critical severity sony neural network libraries vulnerability
Published Apr 4, 2019
·Updated
nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which might be untrusted.
Affected Software
1 affected component
Sony Neural Network Libraries<=1.0.14
Remediation
Patch Available
Event History
Apr 4, 2019
CVE Published
via MITRE·04:19 AM
Data Sourced
via MITRE·04:19 AM
Description
Frequently Asked Questions
1
What is CVE-2019-10844?
CVE-2019-10844 is a vulnerability in Sony Neural Network Libraries (nnabla) through v1.0.14 that relies on the HOME environment variable, which might be untrusted.
2
What is the severity of CVE-2019-10844?
The severity of CVE-2019-10844 is critical, with a severity value of 9.8.
3
How does CVE-2019-10844 affect Sony Neural Network Libraries?
CVE-2019-10844 affects Sony Neural Network Libraries (nnabla) versions up to v1.0.14.
4
How can I fix CVE-2019-10844?
To fix CVE-2019-10844, update Sony Neural Network Libraries to a version higher than v1.0.14.
5
Where can I find more information about CVE-2019-10844?
You can find more information about CVE-2019-10844 at the following link: [https://github.com/sony/nnabla/issues/209](https://github.com/sony/nnabla/issues/209)