First published: Thu Apr 04 2019(Updated: )
nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which might be untrusted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sony Neural Network Libraries | <=1.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10844 is a vulnerability in Sony Neural Network Libraries (nnabla) through v1.0.14 that relies on the HOME environment variable, which might be untrusted.
The severity of CVE-2019-10844 is critical, with a severity value of 9.8.
CVE-2019-10844 affects Sony Neural Network Libraries (nnabla) versions up to v1.0.14.
To fix CVE-2019-10844, update Sony Neural Network Libraries to a version higher than v1.0.14.
You can find more information about CVE-2019-10844 at the following link: [https://github.com/sony/nnabla/issues/209](https://github.com/sony/nnabla/issues/209)