GHSA-m2f8-v8q4-3m59

Suggest an improvement
Source
https://github.com/advisories/GHSA-m2f8-v8q4-3m59
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-m2f8-v8q4-3m59/GHSA-m2f8-v8q4-3m59.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m2f8-v8q4-3m59
Aliases
  • CVE-2023-27506
Published
2023-08-11T03:30:21Z
Modified
2024-02-16T08:13:34.977027Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
Details

Improper buffer restrictions in the Intel(R) Optimization for Tensorflow software before version 2.12 may allow an authenticated user to potentially enable escalation of privilege via local access.

Database specific
{
    "nvd_published_at": "2023-08-11T03:15:23Z",
    "cwe_ids": [
        "CWE-119"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-09-01T21:36:28Z"
}
References

Affected packages

PyPI / intel-tensorflow

Package

Name
intel-tensorflow
View open source insights on deps.dev
Purl
pkg:pypi/intel-tensorflow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12

Affected versions

0.*

0.0.1

1.*

1.12.0
1.13.1
1.13.2
1.14.0
1.15.0
1.15.2

2.*

2.0.0
2.0.1
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.1
2.10.0
2.11.dev202242
2.11.0

PyPI / tensorflow-intel

Package

Name
tensorflow-intel
View open source insights on deps.dev
Purl
pkg:pypi/tensorflow-intel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12

Affected versions

0.*

0.0.1

2.*

2.10.0.dev20220728
2.10.0rc0
2.10.0rc1
2.10.0rc2
2.10.0rc3
2.10.0
2.10.1
2.11.0rc0
2.11.0rc1
2.11.0rc2
2.11.0
2.11.1
2.12.0rc0
2.12.0rc1

PyPI / intel-tensorflow-avx512

Package

Name
intel-tensorflow-avx512
View open source insights on deps.dev
Purl
pkg:pypi/intel-tensorflow-avx512

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12

Affected versions

0.*

0.0.1

2.*

2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.1
2.10.dev202230
2.10.0
2.11.dev202242
2.11.0