OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 2-opencv-heapoverflow-fseek test case.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Feb 19, 2019 | Aug 6, 2017 |
| Gentoo Linux | — | Upgrade media-libs/opencv. | Dec 18, 2017 | Aug 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 5, 2017 |
| Suse | — | Upgrade opencv-docUpgrade opencvUpgrade python3-opencvUpgrade python-opencv-debuginfoUpgrade libopencv3_1Upgrade python3-opencv-qt5-debuginfoUpgrade opencv-qt5-debuginfoUpgrade opencv-qt5-debugsourceUpgrade python-opencv-qt5-debuginfoUpgrade opencv-qt5-develUpgrade libopencv3_1-debuginfoUpgrade opencv-qt5-docUpgrade python3-opencv-debuginfoUpgrade python3-opencv-qt5Upgrade opencv-debuginfoUpgrade opencv-develUpgrade opencv-debugsourceUpgrade python-opencv-qt5Upgrade python-opencvUpgrade opencv-qt5Upgrade libopencv-qt56_3Upgrade libopencv-qt56_3-debuginfo | May 24, 2018 | Aug 6, 2017 |
| Ubuntu | — | Upgrade opencv | Nov 19, 2024 | Aug 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub