A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnerability is the function DecodedBitStreamParser::decodeByteSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-228547.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Jul 30, 2024 | May 10, 2023 |
| Ubuntu | — | Upgrade libopencv-core4.5d (Ubuntu Pro)Upgrade libopencv-dnn4.5d (Ubuntu Pro)Upgrade libopencv-core3.2 (Ubuntu Pro)Upgrade libopencv-objdetect4.5d (Ubuntu Pro)Upgrade libopencv-flann4.5d (Ubuntu Pro)Upgrade libopencv-contrib4.5d (Ubuntu Pro)Upgrade libopencv-imgcodecs4.5d (Ubuntu Pro)Upgrade opencv-data (Ubuntu Pro)Upgrade libopencv-dev (Ubuntu Pro) | Feb 4, 2025 | May 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub