PT-2018-3834 · Intel+1 · Opencv+1

Epeius

·

Published

2018-01-07

·

Updated

2021-11-30

·

CVE-2018-5268

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenCV version 3.3.1
Description A heap-based buffer overflow occurs in the cv::Jpeg2KDecoder::readComponent8u function in modules/imgcodecs/src/grfmt jpeg2000.cpp when parsing a crafted image file, potentially allowing a remote attacker to cause a denial of service.
Recommendations For OpenCV version 3.3.1, consider disabling the cv::Jpeg2KDecoder::readComponent8u function until a patch is available to prevent exploitation of the heap-based buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05956
CVE-2018-5268
DLA-1354-1
DLA-1438-1
DLA-2799-1
GHSA-9G8H-PJM4-Q92P
OPENSUSE-SU-2018_1438-1

Affected Products

Opencv
Suse