Lucene search

K
githubGitHub Advisory DatabaseGHSA-Q799-Q27X-VP7W
HistoryOct 12, 2021 - 10:23 p.m.

Out-of-bounds Write in OpenCV

2021-10-1222:23:21
CWE-120
CWE-787
GitHub Advisory Database
github.com
32
exploitable
heap buffer overflow
opencv
data structure
persistence
json
buffer overflow
heap corruption
code execution
attacker
vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.032

Percentile

91.2%

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0 (corresponds with OpenCV-Python version 4.1.2.30). A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

Affected configurations

Vulners
Node
opencvopencv-contrib-python-headlessRange4.1.2.30
OR
opencvopencv-contrib-pythonRange4.1.2.30
OR
opencvopencv-python-headlessRange4.1.2.30
OR
opencvopencv-pythonRange4.1.2.30
VendorProductVersionCPE
opencvopencv-contrib-python-headless*cpe:2.3:a:opencv:opencv-contrib-python-headless:*:*:*:*:*:*:*:*
opencvopencv-contrib-python*cpe:2.3:a:opencv:opencv-contrib-python:*:*:*:*:*:*:*:*
opencvopencv-python-headless*cpe:2.3:a:opencv:opencv-python-headless:*:*:*:*:*:*:*:*
opencvopencv-python*cpe:2.3:a:opencv:opencv-python:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.032

Percentile

91.2%