CVE-2018-7577

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
24/04/2019
Last modified:
30/04/2019

Description

Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:snappy:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* 1.7.1 (excluding)