In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Feb 19, 2019 | Jan 2, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 2, 2018 |
| Suse | — | Upgrade opencvUpgrade opencv-develUpgrade libopencv-qt56_3-debuginfoUpgrade python-opencv-debuginfoUpgrade python-opencv-qt5-debuginfoUpgrade libopencv3_1Upgrade opencv-qt5Upgrade opencv-docUpgrade python3-opencv-qt5-debuginfoUpgrade opencv-qt5-develUpgrade python3-opencvUpgrade opencv-debuginfoUpgrade libopencv3_1-debuginfoUpgrade opencv-qt5-docUpgrade opencv-qt5-debugsourceUpgrade opencv-debugsourceUpgrade libopencv-qt56_3Upgrade python3-opencv-debuginfoUpgrade python-opencvUpgrade opencv-qt5-debuginfoUpgrade python3-opencv-qt5Upgrade python-opencv-qt5 | May 29, 2018 | Jan 2, 2018 |
| Ubuntu | — | Upgrade opencv | Nov 19, 2024 | Jan 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub