CVE-2024-7776: Arbitrary File Overwrite in onnx/onnx
A vulnerability in the downloadmodel function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7776?
CVE-2024-7776 has been classified as a high severity vulnerability due to its potential for arbitrary file overwrite.
How do I fix CVE-2024-7776?
To remediate CVE-2024-7776, upgrade to onnx version 1.17.0 or later.
Which versions of ONNX are affected by CVE-2024-7776?
CVE-2024-7776 affects ONNX versions up to and including 1.16.1.
What kind of attack does CVE-2024-7776 enable?
CVE-2024-7776 allows for path traversal attacks through malicious tar files, resulting in arbitrary file overwrite.
Who is impacted by CVE-2024-7776?
Developers and users of ONNX versions 1.16.1 and earlier are at risk due to CVE-2024-7776.