CVE-2016-1516
published 2017-04-10CVE-2016-1516: OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.34%
81.8th percentile
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | opencv | < opencv 3.2.0+dfsg-6 (bookworm) | opencv 3.2.0+dfsg-6 (bookworm) |
| opencv | opencv | — | — |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
opencv: Double free vulnerability on crafted image
vendor_redhat·2016-01-13·CVSS 8.8
CVE-2016-1516 [HIGH] CWE-416 opencv: Double free vulnerability on crafted image
opencv: Double free vulnerability on crafted image
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
A double-free flaw was found in the way OpenCV handled processing of image files. This flaw could potentially be used to crash applications using OpenCV by tricking users into processing specially crafted image files.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: opencv (Red Hat Enterprise Linux 6) - Will not fix
Package: opencv (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-1516: opencv - OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary ...
vendor_debian·2016·CVSS 8.8
CVE-2016-1516 [HIGH] CVE-2016-1516: opencv - OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary ...
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-6)
bullseye: resolved (fixed in 3.2.0+dfsg-6)
forky: resolved (fixed in 3.2.0+dfsg-6)
sid: resolved (fixed in 3.2.0+dfsg-6)
trixie: resolved (fixed in 3.2.0+dfsg-6)
OSV
Double Free in OpenCV
osv·2021-10-12
CVE-2016-1516 [HIGH] Double Free in OpenCV
Double Free in OpenCV
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code. This issue was fixed in OpenCV version 3.3.1 (corresponding to OpenCV-Python and and OpenCV-Contrib-Python 3.3.1.11).
GHSA
Double Free in OpenCV
ghsa·2021-10-12
CVE-2016-1516 [HIGH] CWE-415 Double Free in OpenCV
Double Free in OpenCV
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code. This issue was fixed in OpenCV version 3.3.1 (corresponding to OpenCV-Python and and OpenCV-Contrib-Python 3.3.1.11).
OSV
CVE-2016-1516: OpenCV 3
osv·2017-04-10·CVSS 8.8
CVE-2016-1516 [HIGH] CVE-2016-1516: OpenCV 3
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1516 opencv: Double free vulnerability on crafted image
bugzilla·2017-04-19·CVSS 8.8
CVE-2016-1516 [HIGH] CVE-2016-1516 opencv: Double free vulnerability on crafted image
CVE-2016-1516 opencv: Double free vulnerability on crafted image
OpenCV 3.0.0 has a double free issue that allows attackers to crash OpenCV applications.
Upstream issue:
https://github.com/opencv/opencv/issues/5956
The research paper is noted below.
External reference:
https://arxiv.org/pdf/1701.04739.pdf
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
arXiv
Summoning Demons: The Pursuit of Exploitable Bugs in Machine Learning
arxiv_fulltext·2017-01-17
Summoning Demons: The Pursuit of Exploitable Bugs in Machine Learning
Summoning Demons
The Pursuit of Exploitable Bugs in Machine Learning
6
Rock Stevens
Octavian Suciu
Andrew Ruef
Sanghyun Hong
Michael Hicks
Tudor Dumitras
University of Maryland, College Park
[2][]
red
.97 #1 * 1.15 + #2#1 #2
lime
[2][]
red#1 #2
## Abstract
Governments and businesses increasingly rely on data analytics and machine learning (ML) for improving their competitive edge in areas such as consumer satisfaction, threat intelligence, decision making, and product efficiency.
However, by cleverly corrupting a subset of data used as input to a target's ML algorithms, an adversary can perturb outcomes and compromise the effectiveness of ML technology.
While prior work in the field of adversarial
machine learning has studied the impact of input
manipulation on correct ML algorithm
https://arxiv.org/pdf/1701.04739.pdfhttps://github.com/opencv/opencv/issues/5956https://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.htmlhttps://arxiv.org/pdf/1701.04739.pdfhttps://github.com/opencv/opencv/issues/5956https://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.html
2017-04-10
Published