QID 980430
QID 980430: Python (pip) Security Update for opencv-contrib-python-headless (GHSA-fm39-cw8h-3p63)
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1 (OpenCV-Python before 3.4.7.28 and 4.x before 4.1.1.26). There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fm39-cw8h-3p63 for updates pertaining to this vulnerability.
Vendor References
- GHSA-fm39-cw8h-3p63 -
github.com/advisories/GHSA-fm39-cw8h-3p63
CVEs related to QID 980430
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fm39-cw8h-3p63 | opencv-contrib-python |
|
|
| GHSA-fm39-cw8h-3p63 | opencv-contrib-python-headless |
|
|
| GHSA-fm39-cw8h-3p63 | opencv-python |
|
|
| GHSA-fm39-cw8h-3p63 | opencv-python-headless |
|