CVE-2024-27319

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
Configurations

No configuration.

History

30 Mar 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL/ -

29 Mar 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/ -
Summary
  • (es) Las versiones del paquete onnx anteriores a la 1.15.0 inclusive son vulnerables a la lectura fuera de los límites, ya que las funciones ONNX_ASSERT y ONNX_ASSERTM tienen una copia desactivada por una cadena.

23 Feb 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-23 18:15

Updated : 2024-03-30 02:15


NVD link : CVE-2024-27319

Mitre link : CVE-2024-27319

CVE.ORG link : CVE-2024-27319


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read