cbcvebase.
CVE-2017-12864
published 2017-08-15

CVE-2017-12864: In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianopencv< opencv 3.2.0+dfsg-6 (bookworm)opencv 3.2.0+dfsg-6 (bookworm)
opencvopencv<= 3.3.0
opencvopencv>= 0 < 3.2.0+dfsg-63.2.0+dfsg-6
opencvopencv>= 0 < 3.2.0+dfsg-63.2.0+dfsg-6
opencvopencv>= 0 < 3.2.0+dfsg-63.2.0+dfsg-6
opencvopencv>= 0 < 3.2.0+dfsg-63.2.0+dfsg-6

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH