QID 980425
QID 980425: Python (pip) Security Update for opencv-contrib-python-headless (GHSA-m6vm-8g8v-xfjh)
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0 (corresponds with OpenCV-Python 4.1.0.25). A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m6vm-8g8v-xfjh for updates pertaining to this vulnerability.
Vendor References
- GHSA-m6vm-8g8v-xfjh -
github.com/advisories/GHSA-m6vm-8g8v-xfjh
CVEs related to QID 980425
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m6vm-8g8v-xfjh | opencv-contrib-python |
|
|
| GHSA-m6vm-8g8v-xfjh | opencv-contrib-python-headless |
|
|
| GHSA-m6vm-8g8v-xfjh | opencv-python |
|
|
| GHSA-m6vm-8g8v-xfjh | opencv-python-headless |
|