Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14493

Опубликовано: 23 июл. 2019
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp.

A NULL pointer dereference flaw was found in OpenCV in the way the Cascade Classifier algorithm loaded and processed certain classifiers. A remote attacker could exploit this flaw by providing a specially crafted XML file that, when loaded by an application linked to OpenCV, would crash the application causing a denial of service.

Отчет

This flaw did not affect the versions of OpenCV as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include the vulnerable code, which was introduced in a newer version of the library.

Меры по смягчению последствий

Avoid loading cascade classifiers from external untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opencvNot affected
Red Hat Enterprise Linux 7opencvNot affected
Red Hat Enterprise Linux 8opencvNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1797450opencv: NULL pointer dereference in function cv::XMLParser::parse() in persistence_xml.cpp leading to DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in OpenCV before 4.1.1. There is a NULL pointe ...

CVSS3: 7.5
github
больше 4 лет назад

NULL Pointer Dereference in OpenCV.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость функции cv::XMLParser::parse компонента modules/core/src/persistence.cpp библиотеки алгоритмов компьютерного зрения, обработки изображений и численных алгоритмов общего назначения Open Source Computer Vision Library (OpenCV), связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3