QID 980077
QID 980077: Python (pip) Security Update for opencv-contrib-python (GHSA-6v6p-p97v-g2p7)
OpenCV (Open Source Computer Vision Library) through 3.3 (corresponding to OpenCV-Python and OpenCV-Contrib-Python 3.3.0.9) has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 2-opencv-heapoverflow-fseek test case.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6v6p-p97v-g2p7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6v6p-p97v-g2p7 -
github.com/advisories/GHSA-6v6p-p97v-g2p7
CVEs related to QID 980077
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6v6p-p97v-g2p7 | opencv-contrib-python |
|
|
| GHSA-6v6p-p97v-g2p7 | opencv-python |
|