QID 980424
QID 980424: Python (pip) Security Update for opencv-opencv-contrib-python-headless (GHSA-q799-q27x-vp7w)
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0 (corresponds with OpenCV-Python version 4.1.2.30). A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q799-q27x-vp7w for updates pertaining to this vulnerability.
Vendor References
- GHSA-q799-q27x-vp7w -
github.com/advisories/GHSA-q799-q27x-vp7w
CVEs related to QID 980424
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q799-q27x-vp7w | opencv-contrib-python |
|
|
| GHSA-q799-q27x-vp7w | opencv-opencv-contrib-python-headless |
|
|
| GHSA-q799-q27x-vp7w | opencv-python |
|
|
| GHSA-q799-q27x-vp7w | opencv-python-headless |
|