CVE-2017-1000450
published 2018-01-02CVE-2017-1000450: In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.23%
86.9th percentile
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | opencv | < opencv 3.2.0+dfsg-6 (bookworm) | opencv 3.2.0+dfsg-6 (bookworm) |
| opencv | opencv | <= 3.3.0 | — |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Integer Overflow or Wraparound in OpenCV.
osv·2021-10-12
CVE-2017-1000450 [HIGH] Integer Overflow or Wraparound in OpenCV.
Integer Overflow or Wraparound in OpenCV.
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 (corresponding with OpenCV-Python 3.3.0.9) and earlier.
GHSA
Integer Overflow or Wraparound in OpenCV.
ghsa·2021-10-12
CVE-2017-1000450 [HIGH] CWE-190 Integer Overflow or Wraparound in OpenCV.
Integer Overflow or Wraparound in OpenCV.
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 (corresponding with OpenCV-Python 3.3.0.9) and earlier.
OSV
CVE-2017-1000450: In opencv/modules/imgcodecs/src/utils
osv·2018-01-02·CVSS 8.8
CVE-2017-1000450 [HIGH] CVE-2017-1000450: In opencv/modules/imgcodecs/src/utils
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Red Hat
opencv: out of bounds write in functions FillUniColor and FillUniGray in opencv/modules/imgcodecs/src/utils.cpp
vendor_redhat·2017-09-26·CVSS 8.8
CVE-2017-1000450 [HIGH] CWE-787 opencv: out of bounds write in functions FillUniColor and FillUniGray in opencv/modules/imgcodecs/src/utils.cpp
opencv: out of bounds write in functions FillUniColor and FillUniGray in opencv/modules/imgcodecs/src/utils.cpp
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat Enterprise Linux 6 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated
Debian
CVE-2017-1000450: opencv - In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGra...
vendor_debian·2017·CVSS 8.8
CVE-2017-1000450 [HIGH] CVE-2017-1000450: opencv - In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGra...
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-6)
bullseye: resolved (fixed in 3.2.0+dfsg-6)
forky: resolved (fixed in 3.2.0+dfsg-6)
sid: resolved (fixed in 3.2.0+dfsg-6)
trixie: resolved (fixed in 3.2.0+dfsg-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
bugzilla·2018-01-05·CVSS 8.8
CVE-2017-1000450 [HIGH] CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2017-1000450 opencv: out of bounds write in functions FillUniColor and FillUniGray in opencv/modules/imgcodecs/src/utils.cpp
bugzilla·2018-01-05·CVSS 8.8
CVE-2017-1000450 [HIGH] CVE-2017-1000450 opencv: out of bounds write in functions FillUniColor and FillUniGray in opencv/modules/imgcodecs/src/utils.cpp
CVE-2017-1000450 opencv: out of bounds write in functions FillUniColor and FillUniGray in opencv/modules/imgcodecs/src/utils.cpp
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to an integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
[UPSTREAM BUG]
https://github.com/opencv/opencv/issues/9723
[UPSTREAM PATCH]
https://github.com/opencv/opencv/pull/9726/files
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1531611]
---
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
https://github.com/blendin/pocs/blob/master/opencv/0.OOB_Write_FillUniColorhttps://github.com/opencv/opencv/issues/9723https://lists.debian.org/debian-lts-announce/2018/01/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.htmlhttps://github.com/blendin/pocs/blob/master/opencv/0.OOB_Write_FillUniColorhttps://github.com/opencv/opencv/issues/9723https://lists.debian.org/debian-lts-announce/2018/01/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.html
2018-01-02
Published