CVE-2020-28975
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM
5,0
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial
Description
AI Translation Available
svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0082
Percentile
0,7th
Updated
EPSS Score Trend (Last 90 Days)
Application
Scikit-Learn by Scikit-Learn
Version Range Affected
From
0.23.2
(inclusive)
To
1.0.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:scikit-learn:scikit-learn:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://packetstormsecurity.com/files/160281/SciKit-Learn-0.23.2-Denial-Of-Servi…
http://seclists.org/fulldisclosure/2020/Nov/44
https://github.com/cjlin1/libsvm/blob/9a3a9708926dec87d382c43b203f2ca19c2d56a0/…
https://github.com/scikit-learn/scikit-learn/commit/1bf13d567d3cd74854aa8343fd2…
https://github.com/scikit-learn/scikit-learn/issues/18891
https://security.gentoo.org/glsa/202301-03
http://packetstormsecurity.com/files/160281/SciKit-Learn-0.23.2-Denial-Of-Servi…
http://seclists.org/fulldisclosure/2020/Nov/44
https://github.com/cjlin1/libsvm/blob/9a3a9708926dec87d382c43b203f2ca19c2d56a0/…
https://github.com/scikit-learn/scikit-learn/commit/1bf13d567d3cd74854aa8343fd2…
https://github.com/scikit-learn/scikit-learn/issues/18891
https://security.gentoo.org/glsa/202301-03