Oval Definition:oval:org.opensuse.security:def:202015206
Revision Date:2022-06-30Version:1
Title:CVE-2020-15206
Description:

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corruption while loading the model. This can cause a denial of service in products using `tensorflow-serving` or other inference-as-a-service installments. Fixed were added in commits f760f88b4267d981e13f4b302c437ae800445968 and fcfef195637c6e365577829c4d67681695956e7d (both going into TensorFlow 2.2.0 and 2.3.0 but not yet backported to earlier versions). However, this was not enough, as #41097 reports a different failure mode. The issue is patched in commit adf095206f25471e864a8e63a0f1caef53a0e3a6, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2020-15206
openSUSE-SU-2020:1766-1
Mitre CVE-2020-15206
SUSE CVE-2020-15206
openSUSE-SU-2020:1766-1
Platform(s):openSUSE Leap 15.2
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libtensorflow2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2 is signed with openSUSE key
  • OR
  • libtensorflow2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • libtensorflow_cc2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2 is signed with openSUSE key
  • OR
  • libtensorflow_cc2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow_cc2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • libtensorflow_framework2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2 is signed with openSUSE key
  • OR
  • libtensorflow_framework2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow_framework2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2 is signed with openSUSE key
  • OR
  • tensorflow2-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-devel is signed with openSUSE key
  • OR
  • tensorflow2-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-doc is signed with openSUSE key
  • OR
  • tensorflow2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-gnu-hpc is signed with openSUSE key
  • OR
  • tensorflow2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2-lite-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-lite is signed with openSUSE key
  • OR
  • tensorflow2-lite-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-lite-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc-doc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc-doc is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • tensorflow-lite-2.9.1-1.1 is installed
  • OR tensorflow-lite-devel-2.9.1-1.1 is installed
  • BACK