Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14492

Опубликовано: 23 июл. 2019
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

An out-of-bounds read flaw was found in OpenCV in the way the Cascade Classifier algorithm loaded and processed the Haar feature-based cascade classifiers. This flaw allows a remote attacker to provide a specially crafted classifier in the form of an XML file that, when loaded by an application linked to OpenCV, would crash the application, causing a denial of service.

Отчет

The versions of OpenCV as shipped with Red Hat Enterprise Linux 7 and 8 are affected by this flaw. Although it's technically possible that classifiers are loaded from untrusted sources, this is probably an unlikely case in practice.

Меры по смягчению последствий

Avoid loading cascade classifiers from external untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opencvOut of support scope
Red Hat Enterprise Linux 7opencvWill not fix
Red Hat Enterprise Linux 8opencvWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1797445opencv: out-of-bounds read in function HaarEvaluator::OptFeature::calc() in cascadedetect.hpp leading to DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. T ...

CVSS3: 7.5
github
больше 4 лет назад

Out-of-bounds Read and Out-of-bounds Write in OpenCV

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость функции OptFeature() компонента objdetect/src/cascadedetect.hpp библиотеки алгоритмов компьютерного зрения OpenCV, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3