CVE-2019-5063
published 2020-01-03CVE-2019-5063: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can…
PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
20.95%
97.3th percentile
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opencv | < opencv 4.2.0+dfsg-3 (bookworm) | opencv 4.2.0+dfsg-3 (bookworm) |
| opencv | opencv | — | — |
| opencv | opencv | — | — |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| oracle | application_testing_suite | — | — |
| oracle | big_data_spatial_and_graph | < 2.0 | 2.0 |
| oracle | enterprise_manager_base_platform | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Out-of-bounds Write in OpenCV
osv·2021-10-12
CVE-2019-5063 [HIGH] Out-of-bounds Write in OpenCV
Out-of-bounds Write in OpenCV
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0 (corresponds with OpenCV-Python 4.1.0.25). A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
GHSA
Out-of-bounds Write in OpenCV
ghsa·2021-10-12
CVE-2019-5063 [HIGH] CWE-787 Out-of-bounds Write in OpenCV
Out-of-bounds Write in OpenCV
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0 (corresponds with OpenCV-Python 4.1.0.25). A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
OSV
CVE-2019-5063: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4
osv·2020-01-03·CVSS 8.8
CVE-2019-5063 [HIGH] CVE-2019-5063: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
Red Hat
opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file
vendor_redhat·2020-01-02·CVSS 8.8
CVE-2019-5063 [HIGH] CWE-122 opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file
opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
A heap buffer overflow vulnerability was found in the data structure persistence functionality of OpenCV. Specifically, a specially crafted XML file could cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. A remote attacker could exploit this flaw by providing a specially crafted XML file to trigger this vulnerability.
Statement: This flaw
Debian
CVE-2019-5063: opencv - An exploitable heap buffer overflow vulnerability exists in the data structure p...
vendor_debian·2019·CVSS 8.8
CVE-2019-5063 [HIGH] CVE-2019-5063: opencv - An exploitable heap buffer overflow vulnerability exists in the data structure p...
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 4.2.0+dfsg-3)
bullseye: resolved (fixed in 4.2.0+dfsg-3)
forky: resolved (fixed in 4.2.0+dfsg-3)
sid: resolved (fixed in 4.2.0+dfsg-3)
trixie: resolved (fixed in 4.2.0+dfsg-3)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
blogs_talos·2020-01-02·CVSS 8.8
[HIGH] Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
## Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
Dave McDaniel of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered two buffer overflow vulnerabilities in the OpenCV libraries. An attacker could potentially exploit these bugs to cause heap corruptions and potentially code execution. Intel Research originally developed OpenCV in 1999, but it is currently maintained by the non-profit organization OpenCV.org.
OpenCV is used for numerous applications, including facial recognition technology, robotics, motion tracking and various machine learning programs. In accordance with our coordinated disclosure policy, Cisco Talos worked with OpenCV to ensure that these issues are resolved and that an update is available for affected customers.
##
Talos
Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
blogs_talos·2020-01-02·CVSS 8.8
[HIGH] Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
Dave McDaniel of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered two buffer overflow vulnerabilities in the OpenCV libraries. An attacker could potentially exploit these bugs to cause heap corruptions and potentially code execution. Intel Research originally developed OpenCV in 1999, but it is currently maintained by the non-profit organization OpenCV.org.
OpenCV is used for numerous applications, including facial recognition technology, robotics, motion tracking and various machine learning programs.
In accordance with our coordinated disclosure policy, Cisco Talos worked with OpenCV to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability detailsOpenCV XML persistence parser buffer overflow vulnerab
Bugzilla
CVE-2019-5063 opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file
bugzilla·2020-01-11·CVSS 8.8
CVE-2019-5063 [HIGH] CVE-2019-5063 opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file
CVE-2019-5063 opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file
An exploitable heap buffer overflow vulnerability exists in the data structure
persistence functionality of OpenCV 4.1.0. A specially crafted XML file can
cause a buffer overflow, resulting in multiple heap corruptions and potential
code execution. An attacker can provide a specially crafted file to trigger this
vulnerability.
References:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0852
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1790056]
---
External References:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0852
---
Mitigation:
Avoid loading OpenCV data structures from external untrusted XML files.
---
Stat
Bugzilla
CVE-2019-5063 opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file [fedora-all]
bugzilla·2020-01-11·CVSS 8.8
CVE-2019-5063 [HIGH] CVE-2019-5063 opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file [fedora-all]
CVE-2019-5063 opencv: Heap buffer overflow in persistence_xml.cpp while parsing crafted XML file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0852https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://talosintelligence.com/vulnerability_reports/TALOS-2019-0852https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.html
2020-01-03
Published