In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_pitch. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Feb 19, 2019 | Aug 15, 2017 |
| Gentoo Linux | — | Upgrade media-libs/opencv. | Dec 18, 2017 | Aug 15, 2017 |
| Suse | — | Upgrade libopencv3_1Upgrade opencvUpgrade python-opencv-debuginfoUpgrade python-opencv-qt5-debuginfoUpgrade libopencv3_1-debuginfoUpgrade opencv-qt5-debuginfoUpgrade libopencv-qt56_3-debuginfoUpgrade python3-opencvUpgrade python3-opencv-qt5Upgrade opencv-qt5-debugsourceUpgrade libopencv-qt56_3Upgrade opencv-qt5-develUpgrade python3-opencv-qt5-debuginfoUpgrade python3-opencv-debuginfoUpgrade opencv-qt5Upgrade opencv-debugsourceUpgrade python-opencvUpgrade opencv-debuginfoUpgrade python-opencv-qt5Upgrade opencv-qt5-docUpgrade opencv-develUpgrade opencv-doc | May 24, 2018 | Aug 15, 2017 |
| Ubuntu | — | Upgrade opencv | Nov 19, 2024 | Aug 15, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub