Oval Definition:oval:org.opensuse.security:def:202015194
Revision Date:2022-06-30Version:1
Title:CVE-2020-15194
Description:

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_t` and `grad_values_t` are accessed in a similar pattern, only `reverse_index_map_t` is validated to be of proper shape. Hence, malicious users can pass a bad `grad_values_t` to trigger an assertion failure in `vec`, causing denial of service in serving installations. The issue is patched in commit 390611e0d45c5793c7066110af37c8514e6a6c54, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1."
Family:unixClass:vulnerability
Status:Reference(s):CVE-2020-15194
openSUSE-SU-2020:1766-1
Mitre CVE-2020-15194
SUSE CVE-2020-15194
openSUSE-SU-2020:1766-1
Platform(s):openSUSE Leap 15.2
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libtensorflow2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2 is signed with openSUSE key
  • OR
  • libtensorflow2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • libtensorflow_cc2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2 is signed with openSUSE key
  • OR
  • libtensorflow_cc2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow_cc2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • libtensorflow_framework2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2 is signed with openSUSE key
  • OR
  • libtensorflow_framework2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow_framework2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2 is signed with openSUSE key
  • OR
  • tensorflow2-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-devel is signed with openSUSE key
  • OR
  • tensorflow2-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-doc is signed with openSUSE key
  • OR
  • tensorflow2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-gnu-hpc is signed with openSUSE key
  • OR
  • tensorflow2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2-lite-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-lite is signed with openSUSE key
  • OR
  • tensorflow2-lite-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-lite-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc-doc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc-doc is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • tensorflow-lite-2.9.1-1.1 is installed
  • OR tensorflow-lite-devel-2.9.1-1.1 is installed
  • BACK