CVE-2021-29599 - log back

CVE-2021-29599 edited at 14 May 2021 21:55:30
Type
- Unknown
+ Denial of service
CVE-2021-29599 edited at 14 May 2021 21:32:07
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Description
+ A security issue has been found in TensorFlow before version 2.4.2. The implementation of the `Split` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/e2752089ef7ce9bcf3db0ec618ebd23ea119d0c7/tensorflow/lite/kernels/split.cc#L63-L65). An attacker can craft a model such that `num_splits` would be 0.
References
+ https://github.com/tensorflow/tensorflow/security/advisories/GHSA-97wf-p777-86jq
+ https://github.com/tensorflow/tensorflow/commit/b22786e7e9b7bdb6a56936ff29cc7e9968d7bc1d
CVE-2021-29599 created at 14 May 2021 20:37:16
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes