CVE-2023-6656

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has been rated as critical. Affected by this issue is some unknown functionality of the file DFLIMG/DFLJPG.py. The manipulation leads to deserialization. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The identifier of this vulnerability is VDB-247364. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/bayuncao/vul-cve-1 Broken Link
https://vuldb.com/?ctiid.247364 Permissions Required
https://vuldb.com/?id.247364 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:iperov:deepfacelab:df.wf.288res.384.92.72.22:*:*:*:*:*:*:*

History

13 Dec 2023, 21:53

Type Values Removed Values Added
References () https://github.com/bayuncao/vul-cve-1 - () https://github.com/bayuncao/vul-cve-1 - Broken Link
References () https://vuldb.com/?ctiid.247364 - () https://vuldb.com/?ctiid.247364 - Permissions Required
References () https://vuldb.com/?id.247364 - () https://vuldb.com/?id.247364 - Third Party Advisory
First Time Iperov deepfacelab
Iperov
CVSS v2 : 5.1
v3 : 5.0
v2 : 5.1
v3 : 7.5
CPE cpe:2.3:a:iperov:deepfacelab:df.wf.288res.384.92.72.22:*:*:*:*:*:*:*

11 Dec 2023, 12:20

Type Values Removed Values Added
Summary
  • (es) ** NO SOPORTADO CUANDO SE ASIGNÓ ** Se encontró una vulnerabilidad en DF.wf.288res.384.92.72.22 previamente entrenado en DeepFaceLab. Ha sido calificada como crítica. Una función desconocida del archivo DFLIMG/DFLJPG.py es afectada por este problema. La manipulación conduce a la deserialización. El ataque puede lanzarse de forma remota. La complejidad de un ataque es bastante alta. Se sabe que la explotación es difícil. El identificador de esta vulnerabilidad es VDB-247364. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante.

10 Dec 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-10 21:15

Updated : 2024-04-11 01:23


NVD link : CVE-2023-6656

Mitre link : CVE-2023-6656

CVE.ORG link : CVE-2023-6656


JSON object : View

Products Affected

iperov

  • deepfacelab
CWE
CWE-502

Deserialization of Untrusted Data