mindspore@1.1.0 vulnerabilities

MindSpore is a new open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Direct Vulnerabilities

Known vulnerabilities in the mindspore package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Out-of-Bounds

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Out-of-Bounds via the JsonHelper::UpdateArray function of the mindspore/ccsrc/minddata/dataset/util/json_helper.cc file.

How to fix Out-of-Bounds?

A fix was pushed into the master branch but not yet published.

[0,)
  • C
Out-of-bounds Write

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Out-of-bounds Write when an input of type other than int or int32 is passed to the Tile operator's TileInferShape function.

How to fix Out-of-bounds Write?

Upgrade mindspore to version 1.3.0 or higher.

[0.7.0,1.3.0)
  • H
Denial of Service (DoS)

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Denial of Service (DoS) when an attribute depth_multiplier of 0 is used with the DepthwiseConv2D operator, causing division by 0.

How to fix Denial of Service (DoS)?

Upgrade mindspore to version 1.3.0 or higher.

[1.1.0,1.3.0)
  • H
Denial of Service (DoS)

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Denial of Service (DoS) when a value of 0 is used in the parameter block_shape element in the SpaceToBatchInferShape function in, causing division by 0.

How to fix Denial of Service (DoS)?

Upgrade mindspore to version 1.3.0 or higher.

[0.7.0,1.3.0)
  • M
Out-of-bounds Read

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Out-of-bounds Read when the value in a perm element is greater than or equal to the size of the input_shape passed to the TransposeInferShape function.

How to fix Out-of-bounds Read?

Upgrade mindspore to version 1.3.0 or higher.

[0.7.0,1.3.0)
  • H
Denial of Service (DoS)

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Denial of Service (DoS) when a value of 0 is used for the parameter axis_sizes element in the ReduceCPUKernel::Run function, causing division by 0.

How to fix Denial of Service (DoS)?

Upgrade mindspore to version 1.3.0 or higher.

[0.7.0,1.3.0)
  • M
Out-of-bounds Read

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Out-of-bounds Read when shape inference is performed on an input shape size of 0 by the Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, or Gather operators.

How to fix Out-of-bounds Read?

Upgrade mindspore to version 1.3.0 or higher.

[1.1.0,1.3.0)
  • H
Denial of Service (DoS)

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Denial of Service (DoS) when a dimension of the input shape to the SplitBaseCPUKernel::ReSize function is 0, causing division by 0.

How to fix Denial of Service (DoS)?

Upgrade mindspore to version 1.3.0 or higher.

[0.7.0,1.3.0)