OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12597.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Feb 19, 2019 | Sep 4, 2017 |
| Gentoo Linux | — | Upgrade media-libs/opencv. | Dec 18, 2017 | Sep 4, 2017 |
| Suse | — | Upgrade opencv-qt5-docUpgrade python3-opencv-qt5-debuginfoUpgrade python-opencv-qt5Upgrade opencv-debuginfoUpgrade opencv-debugsourceUpgrade libopencv-qt56_3Upgrade libopencv3_1-debuginfoUpgrade opencv-qt5-develUpgrade python3-opencvUpgrade python-opencvUpgrade opencv-qt5-debugsourceUpgrade python3-opencv-debuginfoUpgrade opencv-qt5-debuginfoUpgrade opencvUpgrade opencv-docUpgrade python-opencv-qt5-debuginfoUpgrade opencv-qt5Upgrade opencv-develUpgrade libopencv3_1Upgrade python-opencv-debuginfoUpgrade libopencv-qt56_3-debuginfoUpgrade python3-opencv-qt5 | May 24, 2018 | Sep 4, 2017 |
| Ubuntu | — | Upgrade opencv | Nov 19, 2024 | Sep 4, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub