QID 980428

QID 980428: Python (pip) Security Update for opencv-contrib-python-headless (GHSA-x3rm-644h-67m8)

OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMeanNorm in modules/video/src/dis_flow.cpp.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-x3rm-644h-67m8 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980428

    Software Advisories
    Advisory ID Software Component Link
    GHSA-x3rm-644h-67m8 opencv-contrib-python URL Logo github.com/advisories/GHSA-x3rm-644h-67m8
    GHSA-x3rm-644h-67m8 opencv-contrib-python-headless URL Logo github.com/advisories/GHSA-x3rm-644h-67m8
    GHSA-x3rm-644h-67m8 opencv-python URL Logo github.com/advisories/GHSA-x3rm-644h-67m8
    GHSA-x3rm-644h-67m8 opencv-python-headless URL Logo github.com/advisories/GHSA-x3rm-644h-67m8