CVE-2018-5268
Summary
| CVE | CVE-2018-5268 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-08 05:29:00 UTC |
| Updated | 2021-11-30 18:55:00 UTC |
| Description | In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| A heap based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u · Issue #10541 · opencv/opencv · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Mailing List, Third Party Advisory |
| OpenCV Denial of Service and Heap Buffer Overflow Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1438-1] opencv security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 1354-1] opencv security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 2799-1] opencv security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178871 Debian Security Update for opencv (DLA 2799-1)
- 980078 Python (pip) Security Update for opencv-contrib-python (GHSA-9g8h-pjm4-q92p)