lightgbm@2.0.12 vulnerabilities

LightGBM Python-package

  • latest version

    4.6.0

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the lightgbm package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Out-of-bounds Write

    lightgbm is a gradient boosting framework that uses tree based learning algorithms.

    Affected versions of this package are vulnerable to Out-of-bounds Write in linkers_socket.cpp, used during initialization of distributed training. An attacker can exploit a race condition to connect to a node while it is waiting for a legitimate connection from a configured peer, and send an arbitrary rank value. This may trigger an exploitable crash on the affected node.

    How to fix Out-of-bounds Write?

    Upgrade lightgbm to version 4.6.0 or higher.

    [,4.6.0)