Опубликовано: 30 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.8
Описание
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-contrib-python-headless v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
- https://github.com/opencv/opencv/pull/24274
- https://github.com/opencv/opencv/commit/687fc11626901cff09d2b3b5f331fd59190ad4c7
- https://github.com/advisories/GHSA-j7hp-h8jx-5ppr
- https://github.com/opencv/opencv/wiki/ChangeLog#version481
- https://github.com/pypa/advisory-database/tree/main/vulns/opencv-contrib-python-headless/PYSEC-2023-182.yaml
Пакеты
Наименование
opencv-contrib-python-headless
pip
Затронутые версииВерсия исправления
< 4.8.1.78
4.8.1.78
8.6 High
CVSS4
8.8 High
CVSS3
Дефекты
CWE-787
8.6 High
CVSS4
8.8 High
CVSS3
Дефекты
CWE-787