CVE-2021-35958 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Arbitrary file overwrite |
Description | ** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2114 | tensorflow | 2.7.0-4 | Medium | Vulnerable |
References |
---|
https://vuln.ryotak.me/advisories/52 https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall |