OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 8-opencv-invalid-read-fread test case.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Feb 19, 2019 | Aug 6, 2017 |
| Gentoo Linux | — | Upgrade media-libs/opencv. | Dec 18, 2017 | Aug 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 5, 2017 |
| Suse | — | Upgrade python3-opencv-qt5-debuginfoUpgrade python-opencvUpgrade opencv-debuginfoUpgrade opencvUpgrade opencv-qt5-debuginfoUpgrade opencv-qt5-debugsourceUpgrade python-opencv-qt5-debuginfoUpgrade opencv-qt5-docUpgrade libopencv-qt56_3Upgrade libopencv3_1-debuginfoUpgrade python3-opencv-debuginfoUpgrade opencv-qt5-develUpgrade python3-opencvUpgrade opencv-develUpgrade opencv-docUpgrade python-opencv-qt5Upgrade libopencv3_1Upgrade opencv-debugsourceUpgrade libopencv-qt56_3-debuginfoUpgrade opencv-qt5Upgrade python-opencv-debuginfoUpgrade python3-opencv-qt5 | May 24, 2018 | Aug 6, 2017 |
| Ubuntu | — | Upgrade opencv | Nov 19, 2024 | Aug 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub