From df26c7469c1f2af2e643d43e2e32a6c9142e4885 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Wed, 11 Jan 2023 11:44:03 +0000 Subject: gentoo auto-resync : 11:01:2023 - 11:44:03 --- metadata/glsa/glsa-202301-03.xml | 42 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 metadata/glsa/glsa-202301-03.xml (limited to 'metadata/glsa/glsa-202301-03.xml') diff --git a/metadata/glsa/glsa-202301-03.xml b/metadata/glsa/glsa-202301-03.xml new file mode 100644 index 000000000000..638c1289373c --- /dev/null +++ b/metadata/glsa/glsa-202301-03.xml @@ -0,0 +1,42 @@ + + + + scikit-learn: Denial of Service + A vulnerability was found in scikit-learn which could result in denial of service. + scikit-learn + 2023-01-11 + 2023-01-11 + 758323 + remote + + + 1.1.1 + 1.1.1 + + + +

scikit-learn is a machine learning library for Python.

+
+ +

When supplied with a crafted model SVM, predict() can result in a null pointer dereference.

+
+ +

An attcker capable of providing a crafted model to scikit-learn can result in denial of service.

+
+ +

There is no known workaround at this time.

+
+ +

All scikit-learn users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sci-libs/scikit-learn-1.1.1" + +
+ + CVE-2020-28975 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3