QID 980080

QID 980080: Python (pip) Security Update for opencv-contrib-python (GHSA-jcxv-2j3h-mg59)

OpenCV 3.3.1 (corresponding with opencv-python and opencv-contrib-python 3.3.1.11) has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-jcxv-2j3h-mg59 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980080

    Software Advisories
    Advisory ID Software Component Link
    GHSA-jcxv-2j3h-mg59 opencv-contrib-python URL Logo github.com/advisories/GHSA-jcxv-2j3h-mg59
    GHSA-jcxv-2j3h-mg59 opencv-python URL Logo github.com/advisories/GHSA-jcxv-2j3h-mg59