VDB
Sign up
CRITICAL9.1

PYSEC-2024-223

Quick fix

PYSEC-2024-223 — onnx: upgrade to the fixed version with the command below.

pip install --upgrade 'onnx>=08a399ba75a805b7813ab8936b91d0e274b08287'

Details

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/onnx
Introduced in: 0Fixed in: 08a399ba75a805b7813ab8936b91d0e274b08287
Fixpip install --upgrade 'onnx>=08a399ba75a805b7813ab8936b91d0e274b08287'

References