Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8849-5h85-98qw

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Out-of-bounds Write in OpenCV

In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616

Пакеты

Наименование

opencv-python

pip
Затронутые версииВерсия исправления

<= 4.1.1.26

Отсутствует

Наименование

opencv-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.1.26

Отсутствует

Наименование

opencv-contrib-python

pip
Затронутые версииВерсия исправления

<= 4.1.1.26

Отсутствует

Наименование

opencv-contrib-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.1.26

Отсутствует

EPSS

Процентиль: 8%
0.0003
Низкий

7.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616

CVSS3: 8.1
redhat
больше 6 лет назад

In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616

CVSS3: 7.8
nvd
больше 6 лет назад

In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616

EPSS

Процентиль: 8%
0.0003
Низкий

7.8 High

CVSS3

Дефекты

CWE-787