Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q799-q27x-vp7w

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Out-of-bounds Write in OpenCV

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0 (corresponds with OpenCV-Python version 4.1.2.30). A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

Пакеты

Наименование

opencv-python

pip
Затронутые версииВерсия исправления

<= 4.1.2.30

4.2.0.32

Наименование

opencv-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.2.30

4.2.0.32

Наименование

opencv-contrib-python

pip
Затронутые версииВерсия исправления

<= 4.1.2.30

4.2.0.32

Наименование

opencv-contrib-python-headless

pip
Затронутые версииВерсия исправления

<= 4.1.2.30

4.2.0.32

EPSS

Процентиль: 85%
0.02639
Низкий

8.8 High

CVSS3

Дефекты

CWE-120
CWE-787

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

CVSS3: 8.8
redhat
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

CVSS3: 8.8
nvd
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

CVSS3: 8.8
debian
около 6 лет назад

An exploitable heap buffer overflow vulnerability exists in the data s ...

CVSS3: 8.8
fstec
больше 6 лет назад

Уязвимость функции сохранения структуры данных библиотеки алгоритмов компьютерного зрения, обработки изображений и численных алгоритмов общего назначения Open Source Computer Vision Library (OpenCV), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 85%
0.02639
Низкий

8.8 High

CVSS3

Дефекты

CWE-120
CWE-787