aboutsummaryrefslogtreecommitdiffhomepage
path: root/SECURITY.md
diff options
context:
space:
mode:
authorGravatar Frank Chen <frankchn@google.com>2018-05-29 10:57:01 -0700
committerGravatar TensorFlower Gardener <gardener@tensorflow.org>2018-05-29 11:01:45 -0700
commit3b743eee0bc6f7d23248b3489d46b578cad67dd6 (patch)
tree900b641a2af67e31d38d755d8ae69febac149024 /SECURITY.md
parent920ede367cc07a126820059ec165525687291bea (diff)
Add security notices for recently discovered and patched vulnerabilities.
PiperOrigin-RevId: 198422244
Diffstat (limited to 'SECURITY.md')
-rw-r--r--SECURITY.md5
1 files changed, 4 insertions, 1 deletions
diff --git a/SECURITY.md b/SECURITY.md
index 01886b613e..0a4be37cbc 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -168,7 +168,7 @@ below).
Please use a descriptive subject line for your report email. After the initial
reply to your report, the security team will endeavor to keep you informed of
-the progress being made towards a fix and announcement.
+the progress being made towards a fix and announcement.
In addition, please include the following information along with your report:
@@ -246,5 +246,8 @@ v//Fw6ZeY+HmRDFdirjD7wXtIuER4vqCryIqR6Xe9X8oJXz9L/Jhslc=
| Type | Versions affected | Reported by | Additional Information |
|--------------------|:-----------------:|-----------------------|-----------------------------|
+| TensorFlow Lite TOCO FlatBuffer Parsing Vulnerability | <= 1.7 | Blade Team of Tencent | [security advisory](https://github.com/tensorflow/tensorflow/blob/master/tensorflow/docs_src/security/advisory/tfsa-2018-003.md) |
+| GIF File Parsing Null Pointer Dereference Error | <= 1.5 | Blade Team of Tencent | [security advisory](https://github.com/tensorflow/tensorflow/blob/master/tensorflow/docs_src/security/advisory/tfsa-2018-002.md) |
+| BMP File Parser Out-of-bounds Read | <= 1.6 | Blade Team of Tencent | [security advisory](https://github.com/tensorflow/tensorflow/blob/master/tensorflow/docs_src/security/advisory/tfsa-2018-001.md) |
| Out Of Bounds Read | <=1.4 | Blade Team of Tencent | [issue report](https://github.com/tensorflow/tensorflow/issues/14959) |