scikit-learn 0.23.2 Local Denial of Service

Posted by pabloec20 on Nov 30

[Description]

svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn
0.23.2 and other products, allows attackers to cause a denial of service
(segmentation fault) via a crafted model SVM (introduced via pickle,
json, or any other model permanence technique) with a large value in the
_n_support array.

[CVE ID]

CVE-2020-28975

[Vendor of Product]

SciKit-Learn

[Affected Product Code Base]

scikit-learn – 0.23.2

[Affected…

If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.

Patreon

Original Source