GHSA-634c-v2xv-ffpg
Dashboard / Vulnerabilities / GHSA-634c-v2xv-ffpg
GHSA-634c-v2xv-ffpg
Summary: Out-of-bounds Write in OpenCV
Details: OpenCV (Open Source Computer Vision Library) 3.3 (corresponding to OpenCV-Python 3.3.0.9) has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12597.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-14136, https://github.com/opencv/opencv/issues/9443, https://github.com/opencv/opencv/pull/9448, https://github.com/opencv/opencv-python, https://github.com/xiaoqx/pocs/blob/master/opencv.md, https://lists.debian.org/debian-lts-announce/2018/07/msg00030.html, https://security.gentoo.org/glsa/201712-02
Affected packages
Package
Name: opencv-python
Purl: pkg:pypi/opencv-python
Affected ranges
Type: ECOSYSTEM
Events:
