Description
An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 3.9 | Impact: 2.5Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: Low
Affected Packages2 packages
Also affects: Enterprise Linux 8.0
🔴Vulnerability Details
5OSVopencv vulnerabilities↗2025-02-03 ▶ OSVOut-of-bounds Read in OpenCV↗2021-10-12 ▶ GHSAOut-of-bounds Read in OpenCV↗2021-10-12 ▶ OSVCVE-2019-19624: An out-of-bounds read was discovered in OpenCV before 4↗2019-12-06 ▶ CVEListCVE-2019-19624: An out-of-bounds read was discovered in OpenCV before 4↗2019-12-06 ▶ 📋Vendor Advisories
3UbuntuOpenCV vulnerabilities↗2025-02-03 ▶ Red Hatopencv: out-of-bounds read in DIS optflow algorithm when dealing with small images↗2019-05-14 ▶ DebianCVE-2019-19624: opencv - An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, varia...↗2019 ▶ 💬Community
2BugzillaCVE-2019-19624 opencv: out-of-bounds read in DIS optflow algorithm when dealing with small images↗2019-12-06 ▶ BugzillaCVE-2019-19624 opencv: out-of-bounds read in DIS optflow algorithm when dealing with small images [fedora-all]↗2019-12-06 ▶