NA

CVE-2022-45907

Published: 26/11/2022 Updated: 08/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linuxfoundation pytorch

Vendor Advisories

Debian Bug report logs - #1024903 pytorch: CVE-2022-45907: torchjitannotationsparse_type_line prone to command injection Package: src:pytorch; Maintainer for src:pytorch is Debian Deep Learning Team <debian-ai@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 27 Nov 2022 19:39:01 U ...