VDB
KO
CRITICAL 9.1

PYSEC-2024-223

Details

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / onnx
Introduced in: 0 Fixed in: 08a399ba75a805b7813ab8936b91d0e274b08287
Fix pip install --upgrade 'onnx>=08a399ba75a805b7813ab8936b91d0e274b08287'

References