A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this issue is the function DecodedBitStreamParser::decodeHanziSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to memory leak. The attack may be launched remotely. The name of the patch is 2b62ff6181163eea029ed1cab11363b4996e9cd6. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-228548.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Jul 30, 2024 | May 10, 2023 |
| Ubuntu | — | Upgrade libopencv-dev (Ubuntu Pro)Upgrade libopencv-imgcodecs4.5d (Ubuntu Pro)Upgrade libopencv-contrib4.5d (Ubuntu Pro)Upgrade libopencv-flann4.5d (Ubuntu Pro)Upgrade opencv-data (Ubuntu Pro)Upgrade libopencv-objdetect4.5d (Ubuntu Pro)Upgrade libopencv-core3.2 (Ubuntu Pro)Upgrade libopencv-core4.5d (Ubuntu Pro)Upgrade libopencv-dnn4.5d (Ubuntu Pro) | Feb 4, 2025 | May 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub