Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6vm-8g8v-xfjh

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Out-of-bounds Write in OpenCV

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0 (corresponds with OpenCV-Python 4.1.0.25). A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

Пакеты

Наименование

opencv-python

pip
Затронутые версииВерсия исправления

<= 4.1.0.25

Отсутствует

Наименование

opencv-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.0.25

Отсутствует

Наименование

opencv-contrib-python

pip
Затронутые версииВерсия исправления

<= 4.1.0.25

Отсутствует

Наименование

opencv-contrib-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.0.25

Отсутствует

EPSS

Процентиль: 90%
0.05482
Низкий

8.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

CVSS3: 8.8
redhat
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

CVSS3: 8.8
nvd
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

CVSS3: 8.8
debian
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data s ...

EPSS

Процентиль: 90%
0.05482
Низкий

8.8 High

CVSS3

Дефекты

CWE-787