Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-53644

Опубликовано: 17 июл. 2025
Источник: debian
EPSS Низкий

Описание

OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opencvfixed3.2.0+dfsg-1package

Примечания

  • https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV/

  • https://github.com/opencv/opencv/issues/27271

  • Fixed by: https://github.com/opencv/opencv/commit/a39db41390de546d18962ee1278bd6dbb715f466 (4.12.0)

  • Since opencv/3.1.0+dfsg1-1~exp1 the embedded openjpeg2 copy is excluded

  • completely via Files-Excluded.

EPSS

Процентиль: 17%
0.00056
Низкий

Связанные уязвимости

ubuntu
23 дня назад

OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

CVSS3: 7.3
redhat
23 дня назад

OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

nvd
23 дня назад

OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

EPSS

Процентиль: 17%
0.00056
Низкий