CVE-2017-12862
Summary
| CVE | CVE-2017-12862 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-15 16:29:00 UTC |
| Updated | 2021-11-30 22:07:00 UTC |
| Description | In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| OpenCV: Multiple vulnerabilities (GLSA 201712-02) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| AutoBuffer_heap_overflow in grfmt_pxm.cpp · Issue #9370 · opencv/opencv · GitHub |
MISC |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] [DLA 1438-1] opencv security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2799-1] opencv security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178871 Debian Security Update for opencv (DLA 2799-1)
- 710324 Gentoo Linux OpenCV Multiple Vulnerabilities (GLSA 201712-02)
- 980073 Python (pip) Security Update for opencv-contrib-python (GHSA-5rpc-gwh9-q9fg)