QID 980079

QID 980079: Python (pip) Security Update for opencv-contrib-python (GHSA-m43c-649m-pm48)

In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 (corresponding with OpenCV-Python 3.3.0.9) and earlier.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-m43c-649m-pm48 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980079

    Software Advisories
    Advisory ID Software Component Link
    GHSA-m43c-649m-pm48 opencv-contrib-python URL Logo github.com/advisories/GHSA-m43c-649m-pm48
    GHSA-m43c-649m-pm48 opencv-python URL Logo github.com/advisories/GHSA-m43c-649m-pm48