PT-2018-3834 · Intel+1 · Opencv+1

Epeius

·

Publicado

2018-01-07

·

Atualizado

2021-11-30

·

CVE-2018-5268

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenCV version 3.3.1
Description A heap-based buffer overflow occurs in the cv::Jpeg2KDecoder::readComponent8u function in modules/imgcodecs/src/grfmt jpeg2000.cpp when parsing a crafted image file, potentially allowing a remote attacker to cause a denial of service.
Recommendations For OpenCV version 3.3.1, consider disabling the cv::Jpeg2KDecoder::readComponent8u function until a patch is available to prevent exploitation of the heap-based buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-05956
CVE-2018-5268
DLA-1354-1
DLA-1438-1
DLA-2799-1
GHSA-9G8H-PJM4-Q92P
OPENSUSE-SU-2018_1438-1

Produtos afetados

Opencv
Suse