CRITICAL9.8
PYSEC-2022-43063
Quick fix
PYSEC-2022-43063 — paddlepaddle: upgrade to the fixed version with the command below.
pip install --upgrade 'paddlepaddle>=2.4.0'Details
Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2022-002.md[EVIDENCE]
- https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2022-002.md[FIX]
- https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2022-002.md[ADVISORY]
- https://github.com/advisories/GHSA-gcjf-29m9-888q[ADVISORY]