Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14491

Опубликовано: 01 авг. 2019
Источник: redhat
CVSS3: 6.2

Описание

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrderedcv::HaarEvaluator in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

Отчет

It's possible to cause opencv to attempt to read from incorrect or invalid memory when loading specially crafted classifiers (trained data used for object detection), possibly leading to a crash. Although it's technically possible that classifiers are used from untrusted sources, it's probably an unlikely case in practice.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opencvNot affected
Red Hat Enterprise Linux 7opencvWill not fix
Red Hat Enterprise Linux 8opencvWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1752025opencv: out-of-bounds read in function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp leads to dos

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 6 лет назад

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

CVSS3: 8.2
nvd
больше 6 лет назад

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

CVSS3: 8.2
debian
больше 6 лет назад

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. T ...

CVSS3: 8.2
github
больше 4 лет назад

Out-of-bounds Read in OpenCV

CVSS3: 8.2
fstec
больше 6 лет назад

Уязвимость функции predictOrdered() компонента objdetect/src/cascadedetect.hpp библиотеки алгоритмов компьютерного зрения OpenCV, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

6.2 Medium

CVSS3