Описание
Out-of-bounds Read in OpenCV
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1 (OpenCV-Python before 3.4.7.28 and 4.x before 4.1.1.26). There is an out of bounds read in the function cv::predictOrderedcv::HaarEvaluator in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-14491
- https://github.com/opencv/opencv/issues/15125
- https://github.com/opencv/opencv/compare/33b765d...4a7ca5a
- https://github.com/opencv/opencv/compare/371bba8...ddbd10c
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPFLN6QAX6SUA4XR4NMKKXX26H3TYCVQ
Пакеты
opencv-python
<= 3.4.6.27
3.4.7.28
opencv-python
>= 4.0.0.21, <= 4.1.0.25
4.1.1.26
opencv-python-headless
<= 3.4.6.27
3.4.7.28
opencv-python-headless
>= 4.0.0.21, <= 4.1.0.25
4.1.1.26
opencv-contrib-python
<= 3.4.6.27
3.4.7.28
opencv-contrib-python
>= 4.0.0.21, <= 4.1.0.25
4.1.1.26
opencv-contrib-python-headless
<= 3.4.6.27
3.4.7.28
opencv-contrib-python-headless
>= 4.0.0.21, <= 4.1.0.25
4.1.1.26
Связанные уязвимости
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. T ...
Уязвимость функции predictOrdered() компонента objdetect/src/cascadedetect.hpp библиотеки алгоритмов компьютерного зрения OpenCV, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании