CVE-2019-19624Out-of-bounds Read in Opencv

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 80.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateFeb 3

Description

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 3.9 | Impact: 2.5

Affected Packages2 packages

NVDopencv/opencv< 4.1.1
Debianopencv/opencv< 4.1.2+dfsg-3+3

Also affects: Enterprise Linux 8.0

Patches

🔴Vulnerability Details

5
OSV
opencv vulnerabilities2025-02-03
OSV
Out-of-bounds Read in OpenCV2021-10-12
GHSA
Out-of-bounds Read in OpenCV2021-10-12
OSV
CVE-2019-19624: An out-of-bounds read was discovered in OpenCV before 42019-12-06
CVEList
CVE-2019-19624: An out-of-bounds read was discovered in OpenCV before 42019-12-06

📋Vendor Advisories

3
Ubuntu
OpenCV vulnerabilities2025-02-03
Red Hat
opencv: out-of-bounds read in DIS optflow algorithm when dealing with small images2019-05-14
Debian
CVE-2019-19624: opencv - An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, varia...2019

💬Community

2
Bugzilla
CVE-2019-19624 opencv: out-of-bounds read in DIS optflow algorithm when dealing with small images2019-12-06
Bugzilla
CVE-2019-19624 opencv: out-of-bounds read in DIS optflow algorithm when dealing with small images [fedora-all]2019-12-06
CVE-2019-19624 — Out-of-bounds Read in Opencv | cvebase