CVE-2018-7714Reachable Assertion in Opencv

Severity
7.5HIGHNVD
EPSS
0.4%
top 38.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 5
Latest updateMay 13

Description

The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (pixels <= (1<<30)) may be false. Note: “OpenCV CV_Assert is not an assertion (C-like assert()), it is regular C++ exception which can raised in case of invalid or non-supported parameters.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDopencv/opencv3.4.1

🔴Vulnerability Details

3
GHSA
GHSA-2862-4mgm-j6fv: ** DISPUTED ** The validateInputImageSize function in modules/imgcodecs/src/loadsave2022-05-13
CVEList
CVE-2018-7714: The validateInputImageSize function in modules/imgcodecs/src/loadsave2018-03-05
OSV
CVE-2018-7714: The validateInputImageSize function in modules/imgcodecs/src/loadsave2018-03-05

📋Vendor Advisories

1
Red Hat
opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp2018-03-05

💬Community

2
Bugzilla
CVE-2018-7712 CVE-2018-7713 CVE-2018-7714 opencv: various flaws [fedora-all]2018-03-08
Bugzilla
CVE-2018-7714 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp2018-03-08
CVE-2018-7714 — Reachable Assertion in Opencv | cvebase