OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow in the cv::BmpDecoder::readData function in modules/imgcodecs/src/grfmt_bmp.cpp when reading an image file by using cv::imread, as demonstrated by the 4-buf-overflow-readData-memcpy test case.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Feb 19, 2019 | Aug 6, 2017 |
| Gentoo Linux | — | Upgrade media-libs/opencv. | Dec 18, 2017 | Aug 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 5, 2017 |
| Suse | — | Upgrade opencv-qt5-debugsourceUpgrade python3-opencv-debuginfoUpgrade opencv-debugsourceUpgrade libopencv-qt56_3Upgrade python3-opencvUpgrade python-opencvUpgrade opencv-debuginfoUpgrade python3-opencv-qt5-debuginfoUpgrade opencv-qt5Upgrade python-opencv-debuginfoUpgrade opencv-qt5-docUpgrade opencv-qt5-debuginfoUpgrade libopencv3_1Upgrade libopencv3_1-debuginfoUpgrade opencv-qt5-develUpgrade python-opencv-qt5Upgrade python3-opencv-qt5Upgrade libopencv-qt56_3-debuginfoUpgrade opencv-develUpgrade python-opencv-qt5-debuginfoUpgrade opencvUpgrade opencv-doc | May 24, 2018 | Aug 6, 2017 |
| Ubuntu | — | Upgrade opencv | Nov 19, 2024 | Aug 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub