MindSpore vulnerable to memory corruption
Moderate severity
GitHub Reviewed
Published
May 30, 2023
to the GitHub Advisory Database
•
Updated Sep 25, 2024
Description
Published by the National Vulnerability Database
May 30, 2023
Published to the GitHub Advisory Database
May 30, 2023
Reviewed
Jun 6, 2023
Last updated
Sep 25, 2024
A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the function
JsonHelper::UpdateArray
of the filemindspore/ccsrc/minddata/dataset/util/json_helper.cc
. The manipulation leads to memory corruption. The name of the patch is 30f4729ea2c01e1ed437ba92a81e2fc098d608a9. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-230176.References