Oval Definition:oval:org.opensuse.security:def:202028975
Revision Date:2022-06-30Version:1
Title:CVE-2020-28975
Description:

** DISPUTED ** svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2020-28975
SUSE CVE-2020-28975
Platform(s):openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • python310-scikit-learn-1.0.2-1.1 is installed
  • OR python38-scikit-learn-1.0.2-1.1 is installed
  • OR python39-scikit-learn-1.0.2-1.1 is installed
  • BACK