PT-2017-4343 · Intel+1 · Opencv+1

Scdeny

·

Published

2017-08-15

·

Updated

2021-11-30

·

CVE-2017-12863

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenCV versions 3.3 and earlier
Description: The issue is related to an integer overflow in the PxMDecoder::readData function in opencv/modules/imgcodecs/src/grfmt pxm.cpp. This can lead to remote code execution or denial of service if the image is from a remote source. The vulnerability may allow an attacker to access confidential data, compromise its integrity, and cause a denial of service using a specially crafted file.
Recommendations: For OpenCV versions 3.3 and earlier, consider disabling the PxMDecoder::readData function until a patch is available to prevent potential remote code execution or denial of service. Restrict access to remote images to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07608
CVE-2017-12863
DLA-1117-1
DLA-1438-1
DLA-2799-1
GHSA-WQ8F-WVQP-XVVM
OPENSUSE-SU-2018_1385-1

Affected Products

Opencv
Suse