CVE-2024-5187: Critical Security Fix for onnx in Fedora 40
Summary
onnx provides an open source format for AI models, both deep learning and
traditional ML. It defines an extensible computation graph model, as well as
definitions of built-in operators and standard data types.
Update Information:
Security fix for CVE-2024-5187
Change Log
* Tue Jul 2 2024 Alejandro Alvarez Ayllon
References
[ 1 ] Bug #2290806 - CVE-2024-5187 onnx: arbitrary file overwrite in download_model_with_test_data
https://bugzilla.redhat.com/show_bug.cgi?id=2290806
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d9c7181a19' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label