PaddlePaddle vulnerable to code injection via winstr
Critical severity
GitHub Reviewed
Published
Nov 26, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Nov 26, 2022
Published to the GitHub Advisory Database
Nov 26, 2022
Reviewed
Nov 30, 2022
Last updated
Jan 27, 2023
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.
References