PT-2019-6432 · Opencv+3 · Opencv-Python+4

Vasiliev-Vb

·

Publicado

2019-05-14

·

Atualizado

2025-02-03

·

CVE-2019-19624

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenCV versions prior to 4.1.1 OpenCV-Python versions prior to 4.1.0.25
Description An out-of-bounds read issue was discovered in the calc() and ocl calc() functions within the dis flow.cpp component of OpenCV. This occurs because the coarsest scale variable is assumed to be greater than or equal to finest scale, which is not true when handling small images. As a result, it leads to an out-of-bounds read of the heap-allocated arrays Ux and Uy. This could potentially allow a remote attacker to access confidential data and cause a denial of service.
Recommendations For OpenCV versions prior to 4.1.1, update to version 4.1.1 or later to resolve the issue. For OpenCV-Python versions prior to 4.1.0.25, update to version 4.1.0.25 or later to resolve the issue. As a temporary workaround, consider restricting the use of the calc() and ocl calc() functions in dis flow.cpp when dealing with small images until a patch is available.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-06968
CVE-2019-19624
GHSA-JGGW-2Q6G-C3M6
USN-7247-1

Produtos afetados

Astra Linux
Linuxmint
Opencv
Opencv-Python
Ubuntu