Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jggw-2q6g-c3m6

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Out-of-bounds Read in OpenCV

An out-of-bounds read was discovered in OpenCV before 4.1.1 (OpenCV-Python before 4.1.0.25). Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

Пакеты

Наименование

opencv-python

pip
Затронутые версииВерсия исправления

<= 4.1.0.24

4.1.0.25

Наименование

opencv-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.0.24

4.1.0.25

Наименование

opencv-contrib-python

pip
Затронутые версииВерсия исправления

<= 4.1.0.24

4.1.0.25

Наименование

opencv-contrib-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.0.24

4.1.0.25

EPSS

Процентиль: 46%
0.0023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

CVSS3: 5.3
redhat
больше 6 лет назад

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

CVSS3: 6.5
nvd
около 6 лет назад

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

CVSS3: 6.5
debian
около 6 лет назад

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifica ...

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость переменной coarsest_scale функций calc() и ocl_calc() компонента dis_flow.cpp библиотеки алгоритмов компьютерного зрения, обработки изображений и численных алгоритмов общего назначения Open Source Computer Vision Library (OpenCV), связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

EPSS

Процентиль: 46%
0.0023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-125