CVE-2016-1517
published 2017-04-10CVE-2016-1517: OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.03%
60.2th percentile
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opencv | < opencv 3.2.0+dfsg-6 (bookworm) | opencv 3.2.0+dfsg-6 (bookworm) |
| opencv | opencv | — | — |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
opencv: Remote DoS via vectors involving corrupt chunks
vendor_redhat·2016-01-13·CVSS 5.5
CVE-2016-1517 [MEDIUM] opencv: Remote DoS via vectors involving corrupt chunks
opencv: Remote DoS via vectors involving corrupt chunks
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
A denial of service flaw was found in the way OpenCV handled processing of image files. This flaw could potentially be used to crash applications using OpenCV by tricking users into processing specially crafted image files.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: opencv (Red Hat Enterprise Linux 6) - Will not fix
Package: opencv (Red Hat Enterprise Linux 7) - Wi
Debian
CVE-2016-1517: opencv - OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via...
vendor_debian·2016·CVSS 5.5
CVE-2016-1517 [MEDIUM] CVE-2016-1517: opencv - OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via...
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-6)
bullseye: resolved (fixed in 3.2.0+dfsg-6)
forky: resolved (fixed in 3.2.0+dfsg-6)
sid: resolved (fixed in 3.2.0+dfsg-6)
trixie: resolved (fixed in 3.2.0+dfsg-6)
GHSA
Improper Input Validation in OpenCV
ghsa·2021-10-12
CVE-2016-1517 [MEDIUM] CWE-20 Improper Input Validation in OpenCV
Improper Input Validation in OpenCV
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks. This issue was fixed in OpenCV version 3.3.1 (corresponding to OpenCV 3.3.1.11).
OSV
Improper Input Validation in OpenCV
osv·2021-10-12
CVE-2016-1517 [MEDIUM] Improper Input Validation in OpenCV
Improper Input Validation in OpenCV
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks. This issue was fixed in OpenCV version 3.3.1 (corresponding to OpenCV 3.3.1.11).
OSV
CVE-2016-1517: OpenCV 3
osv·2017-04-10·CVSS 5.5
CVE-2016-1517 [MEDIUM] CVE-2016-1517: OpenCV 3
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
No detection rules found.
No public exploits indexed.
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
arXiv
Summoning Demons: The Pursuit of Exploitable Bugs in Machine Learning
arxiv_fulltext·2017-01-17
Summoning Demons: The Pursuit of Exploitable Bugs in Machine Learning
Summoning Demons
The Pursuit of Exploitable Bugs in Machine Learning
6
Rock Stevens
Octavian Suciu
Andrew Ruef
Sanghyun Hong
Michael Hicks
Tudor Dumitras
University of Maryland, College Park
[2][]
red
.97 #1 * 1.15 + #2#1 #2
lime
[2][]
red#1 #2
## Abstract
Governments and businesses increasingly rely on data analytics and machine learning (ML) for improving their competitive edge in areas such as consumer satisfaction, threat intelligence, decision making, and product efficiency.
However, by cleverly corrupting a subset of data used as input to a target's ML algorithms, an adversary can perturb outcomes and compromise the effectiveness of ML technology.
While prior work in the field of adversarial
machine learning has studied the impact of input
manipulation on correct ML algorithm
Bugzilla
CVE-2016-1517 opencv: Remote DoS via vectors involving corrupt chunks
bugzilla·2017-04-19·CVSS 5.5
CVE-2016-1517 [MEDIUM] CVE-2016-1517 opencv: Remote DoS via vectors involving corrupt chunks
CVE-2016-1517 opencv: Remote DoS via vectors involving corrupt chunks
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
Upstream issue:
https://github.com/opencv/opencv/issues/5956
The research paper is noted below.
External reference:
https://arxiv.org/pdf/1701.04739.pdf
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
2017-04-10
Published