CVE-2017-1000450
Summary
| CVE | CVE-2017-1000450 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-02 17:29:00 UTC |
| Updated | 2021-11-30 22:05:00 UTC |
| Description | In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 1438-1] opencv security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| Out of bounds write causes Segmentation Fault · Issue #9723 · opencv/opencv · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 2799-1] opencv security update |
MLIST |
lists.debian.org |
|
| pocs/0.OOB_Write_FillUniColor at master · blendin/pocs · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| [SECURITY] [DLA 1235-1] opencv security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178871 Debian Security Update for opencv (DLA 2799-1)
- 980079 Python (pip) Security Update for opencv-contrib-python (GHSA-m43c-649m-pm48)