Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-53644

Опубликовано: 17 июл. 2025
Источник: debian
EPSS Низкий

Описание

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opencvfixed3.2.0+dfsg-1package

Примечания

  • https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV/

  • https://github.com/opencv/opencv/issues/27271

  • Fixed by: https://github.com/opencv/opencv/commit/a39db41390de546d18962ee1278bd6dbb715f466 (4.12.0)

  • Since opencv/3.1.0+dfsg1-1~exp1 the embedded openjpeg2 copy is excluded

  • completely via Files-Excluded.

EPSS

Процентиль: 30%
0.00371
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

CVSS3: 7.3
redhat
около 1 года назад

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

CVSS3: 9.8
nvd
около 1 года назад

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

EPSS

Процентиль: 30%
0.00371
Низкий
Уязвимость CVE-2025-53644