PT-2017-4343 · Intel+1 · Opencv+1

Scdeny

·

Publicado

2017-08-15

·

Atualizado

2021-11-30

·

CVE-2017-12863

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenCV versions 3.3 and earlier
Description: The issue is related to an integer overflow in the PxMDecoder::readData function in opencv/modules/imgcodecs/src/grfmt pxm.cpp. This can lead to remote code execution or denial of service if the image is from a remote source. The vulnerability may allow an attacker to access confidential data, compromise its integrity, and cause a denial of service using a specially crafted file.
Recommendations: For OpenCV versions 3.3 and earlier, consider disabling the PxMDecoder::readData function until a patch is available to prevent potential remote code execution or denial of service. Restrict access to remote images to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-07608
CVE-2017-12863
DLA-1117-1
DLA-1438-1
DLA-2799-1
GHSA-WQ8F-WVQP-XVVM
OPENSUSE-SU-2018_1385-1

Produtos afetados

Opencv
Suse