CVE-2018-5269
published 2018-01-08CVE-2018-5269: In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.37%
69.1th percentile
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | opencv | < opencv 3.2.0+dfsg-6 (bookworm) | opencv 3.2.0+dfsg-6 (bookworm) |
| android | — | — | |
| opencv | opencv | — | — |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-6 | 3.2.0+dfsg-6 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Reachable Assertion in OpenCV.
ghsa·2021-10-12
CVE-2018-5269 [MEDIUM] CWE-617 Reachable Assertion in OpenCV.
Reachable Assertion in OpenCV.
In OpenCV 3.3.1 (corresponds with OpenCV-Python 3.3.1.11), an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
OSV
Reachable Assertion in OpenCV.
osv·2021-10-12
CVE-2018-5269 [MEDIUM] Reachable Assertion in OpenCV.
Reachable Assertion in OpenCV.
In OpenCV 3.3.1 (corresponds with OpenCV-Python 3.3.1.11), an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
OSV
CVE-2018-5269: In OpenCV 3
osv·2018-01-08·CVSS 5.5
CVE-2018-5269 [MEDIUM] CVE-2018-5269: In OpenCV 3
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
Android
CVE-2018-5269: Android Security Bulletin 2019-02-01
CVE: CVE-2018-5269
Severity: HIGH
Type: RCE
Affected AOSP versions: 7
vendor_android·2019-02-01·CVSS 5.5
CVE-2018-5269 [MEDIUM] CVE-2018-5269: Android Security Bulletin 2019-02-01
CVE: CVE-2018-5269
Severity: HIGH
Type: RCE
Affected AOSP versions: 7
Android Security Bulletin 2019-02-01
CVE: CVE-2018-5269
Severity: HIGH
Type: RCE
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-78029727*
Red Hat
opencv: Assertion failure due to incorrect integer cast
vendor_redhat·2018-01-07·CVSS 5.5
CVE-2018-5269 [MEDIUM] CWE-617 opencv: Assertion failure due to incorrect integer cast
opencv: Assertion failure due to incorrect integer cast
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
Package: opencv (Red Hat Enterprise Linux 6) - Will not fix
Package: opencv (Red Hat Enterprise Linux 7) - Will not fix
Package: opencv (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2018-5269: opencv - In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modu...
vendor_debian·2018·CVSS 5.5
CVE-2018-5269 [MEDIUM] CVE-2018-5269: opencv - In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modu...
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-6)
bullseye: resolved (fixed in 3.2.0+dfsg-6)
forky: resolved (fixed in 3.2.0+dfsg-6)
sid: resolved (fixed in 3.2.0+dfsg-6)
trixie: resolved (fixed in 3.2.0+dfsg-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5269 opencv: Assertion failure due to incorrect integer cast
bugzilla·2018-01-09·CVSS 5.5
CVE-2018-5269 [MEDIUM] CVE-2018-5269 opencv: Assertion failure due to incorrect integer cast
CVE-2018-5269 opencv: Assertion failure due to incorrect integer cast
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast. A crafted file could cause the application to crash.
Upstream issue:
https://github.com/opencv/opencv/issues/10540
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1531611]
Bugzilla
CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
bugzilla·2018-01-05·CVSS 8.8
CVE-2017-1000450 [HIGH] CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
CVE-2017-1000450 CVE-2018-5268 CVE-2018-5269 opencv: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
arXiv
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
arxiv_fulltext·2025-06-11
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
: Is Your "Clean" Vulnerability Dataset Really Solvable?
Exposing and Trapping Undecidable Patches and Beyond
@IEEEauthorhalign
@IEEEauthorhalign
Zeyu Gao1 1Equal contribution
Tsinghua University
[email protected]
Junlin Zhou1
Sichuan University
[email protected]
Bolun Zhang
Institute of Information Engineering,
Chinese Academy of Sciences
[email protected]
Yi He
Wuhan University
[email protected]
Chao Zhang22Corresponding author
Tsinghua University
[email protected]
Yuxin Cui
Tsinghua University
[email protected]
Hao Wang
Tsinghua University
[email protected]
## Abstract
The quantity and quality of vulnerability datasets are essential for developing deep learning solutions to vulnerability-related tasks. Due
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
http://www.securityfocus.com/bid/106945https://github.com/opencv/opencv/issues/10540https://lists.debian.org/debian-lts-announce/2018/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.htmlhttp://www.securityfocus.com/bid/106945https://github.com/opencv/opencv/issues/10540https://lists.debian.org/debian-lts-announce/2018/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00028.html
2018-01-08
Published