QID 980081

QID 980081: Python (pip) Security Update for opencv-contrib-python (GHSA-267x-w5hx-8hjr)

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects OpenCV 3.3 (corresponding with OpenCV-Python version 3.3.0.9) and earlier.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-267x-w5hx-8hjr for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980081

    Software Advisories
    Advisory ID Software Component Link
    GHSA-267x-w5hx-8hjr opencv-contrib-python URL Logo github.com/advisories/GHSA-267x-w5hx-8hjr
    GHSA-267x-w5hx-8hjr opencv-python URL Logo github.com/advisories/GHSA-267x-w5hx-8hjr