Опубликовано: 30 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.8
Описание
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
- https://github.com/opencv/opencv/pull/24274
- https://github.com/opencv/opencv/commit/687fc11626901cff09d2b3b5f331fd59190ad4c7
- https://github.com/opencv/opencv/wiki/ChangeLog#version481
- https://github.com/pypa/advisory-database/tree/main/vulns/opencv-python/PYSEC-2023-183.yaml
Пакеты
Наименование
opencv-python
pip
Затронутые версииВерсия исправления
< 4.8.1.78
4.8.1.78
8.6 High
CVSS4
8.8 High
CVSS3
Дефекты
CWE-787
8.6 High
CVSS4
8.8 High
CVSS3
Дефекты
CWE-787