CVE-2018-5268
published 2018-01-08CVE-2018-5268: In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.51%
71.7th percentile
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | opencv | < opencv 3.2.0+dfsg-6 (bookworm) | opencv 3.2.0+dfsg-6 (bookworm) |
| android | — | — | |
| opencv | opencv | — | — |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2018-5268: Android Security Bulletin 2019-02-01
CVE: CVE-2018-5268
Severity: HIGH
Type: RCE
Affected AOSP versions: 7
vendor_android·2019-02-01·CVSS 5.5
CVE-2018-5268 [MEDIUM] CVE-2018-5268: Android Security Bulletin 2019-02-01
CVE: CVE-2018-5268
Severity: HIGH
Type: RCE
Affected AOSP versions: 7
Android Security Bulletin 2019-02-01
CVE: CVE-2018-5268
Severity: HIGH
Type: RCE
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-78029634*
Red Hat
opencv: Heap-based buffer overflow in cv::Jpeg2KDecoder::readComponent8u
vendor_redhat·2018-01-07·CVSS 5.5
CVE-2018-5268 [MEDIUM] CWE-122 opencv: Heap-based buffer overflow in cv::Jpeg2KDecoder::readComponent8u
opencv: Heap-based buffer overflow in cv::Jpeg2KDecoder::readComponent8u
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
Package: opencv (Red Hat Enterprise Linux 6) - Will not fix
Package: opencv (Red Hat Enterprise Linux 7) - Will not fix
Package: opencv (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2018-5268: opencv - In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::read...
vendor_debian·2018·CVSS 5.5
CVE-2018-5268 [MEDIUM] CVE-2018-5268: opencv - In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::read...
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-6)
bullseye: resolved (fixed in 3.2.0+dfsg-6)
forky: resolved (fixed in 3.2.0+dfsg-6)
sid: resolved (fixed in 3.2.0+dfsg-6)
trixie: resolved (fixed in 3.2.0+dfsg-6)
OSV
Out-of-bounds Write in OpenCV.
osv·2021-10-12
CVE-2018-5268 [MEDIUM] Out-of-bounds Write in OpenCV.
Out-of-bounds Write in OpenCV.
In OpenCV 3.3.1 (corresponding with OpenCV-Python 3.3.1.11), a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
GHSA
Out-of-bounds Write in OpenCV.
ghsa·2021-10-12
CVE-2018-5268 [MEDIUM] CWE-787 Out-of-bounds Write in OpenCV.
Out-of-bounds Write in OpenCV.
In OpenCV 3.3.1 (corresponding with OpenCV-Python 3.3.1.11), a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
OSV
CVE-2018-5268: In OpenCV 3
osv·2018-01-08·CVSS 5.5
CVE-2018-5268 [MEDIUM] CVE-2018-5268: In OpenCV 3
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5268 opencv: Heap-based buffer overflow in cv::Jpeg2KDecoder::readComponent8u
bugzilla·2018-01-09·CVSS 5.5
CVE-2018-5268 [MEDIUM] CVE-2018-5268 opencv: Heap-based buffer overflow in cv::Jpeg2KDecoder::readComponent8u
CVE-2018-5268 opencv: Heap-based buffer overflow in cv::Jpeg2KDecoder::readComponent8u
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file. This could cause the application to crash.
Upstream issue:
https://github.com/opencv/opencv/issues/10541
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1531611]
Bugzilla
CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
bugzilla·2018-01-05·CVSS 8.8
CVE-2017-1000450 [HIGH] CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
arXiv
Security for Machine Learning-based Software Systems: a survey of threats, practices and challenges
arxiv_fulltext·2023-12-17
Security for Machine Learning-based Software Systems: a survey of threats, practices and challenges
[Literature review]Security for Machine Learning-based Software Systems: a survey of threats, practices and challenges
Huaming Chen
The University of Sydney
Sydney
Australia
[email protected]
M. Ali Babar
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Adelaide
Australia
Cyber Security Cooperative Research Centre
Australia
[email protected]
Huaming Chen and M. Ali Babar
## Abstract
The rapid development of Machine Learning (ML) has demonstrated superior performance in many areas, such as computer vision, video and speech recognition. It has now been increasingly leveraged in software systems to automate the core tasks. However, how to securely develop the machine learning-based modern software systems (MLBSS) remain
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
http://www.securityfocus.com/bid/106945https://github.com/opencv/opencv/issues/10541https://lists.debian.org/debian-lts-announce/2018/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.htmlhttp://www.securityfocus.com/bid/106945https://github.com/opencv/opencv/issues/10541https://lists.debian.org/debian-lts-announce/2018/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.html
2018-01-08
Published