QID 980426

QID 980426: Python (pip) Security Update for opencv-contrib-python-headless (GHSA-jggw-2q6g-c3m6)

An out-of-bounds read was discovered in OpenCV before 4.1.1 (OpenCV-Python before 4.1.0.25). Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to refer to GHSA-jggw-2q6g-c3m6 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980426

    Software Advisories
    Advisory ID Software Component Link
    GHSA-jggw-2q6g-c3m6 opencv-contrib-python URL Logo github.com/advisories/GHSA-jggw-2q6g-c3m6
    GHSA-jggw-2q6g-c3m6 opencv-contrib-python-headless URL Logo github.com/advisories/GHSA-jggw-2q6g-c3m6
    GHSA-jggw-2q6g-c3m6 opencv-python URL Logo github.com/advisories/GHSA-jggw-2q6g-c3m6
    GHSA-jggw-2q6g-c3m6 opencv-python-headless URL Logo github.com/advisories/GHSA-jggw-2q6g-c3m6