OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an image file by using cv::imread.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Feb 19, 2019 | Aug 6, 2017 |
| Gentoo Linux | — | Upgrade media-libs/opencv. | Dec 18, 2017 | Aug 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 5, 2017 |
| Suse | — | Upgrade libopencv3_1Upgrade opencv-qt5-develUpgrade opencv-qt5Upgrade python3-opencvUpgrade opencv-qt5-docUpgrade opencv-qt5-debugsourceUpgrade opencv-debuginfoUpgrade python-opencv-debuginfoUpgrade python-opencvUpgrade python3-opencv-qt5-debuginfoUpgrade python3-opencv-debuginfoUpgrade libopencv-qt56_3Upgrade opencv-qt5-debuginfoUpgrade python3-opencv-qt5Upgrade python-opencv-qt5Upgrade opencv-docUpgrade opencvUpgrade libopencv-qt56_3-debuginfoUpgrade python-opencv-qt5-debuginfoUpgrade opencv-debugsourceUpgrade libopencv3_1-debuginfoUpgrade opencv-devel | May 24, 2018 | Aug 6, 2017 |
| Ubuntu | — | Upgrade opencv | Nov 19, 2024 | Aug 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub