CVE-2019-5064
published 2020-01-03CVE-2019-5064: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted…
PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
10.62%
95.3th percentile
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opencv | < opencv 4.2.0+dfsg-3 (bookworm) | opencv 4.2.0+dfsg-3 (bookworm) |
| opencv | opencv | — | — |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| opencv | opencv | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| opencv | opencv | >= 4.0.0 < 4.2.0 | 4.2.0 |
| oracle | application_testing_suite | — | — |
| oracle | big_data_spatial_and_graph | < 2.0 | 2.0 |
| oracle | enterprise_manager_base_platform | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (OpenCV) — CVE-2019-5064
vendor_oracle·2021-07-15·CVSS 8.8
CVE-2019-5064 [HIGH] Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (OpenCV) — CVE-2019-5064
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (OpenCV) vulnerability
CVE: CVE-2019-5064
CVSS: 8.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (OpenCV) — CVE-2019-5064
vendor_oracle·2021-04-15·CVSS 8.8
CVE-2019-5064 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (OpenCV) — CVE-2019-5064
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (OpenCV) vulnerability
CVE: CVE-2019-5064
CVSS: 8.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Red Hat
opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file
vendor_redhat·2020-01-02·CVSS 8.8
CVE-2019-5064 [HIGH] CWE-122 opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file
opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
A heap buffer overflow vulnerability was found in the data structure persistence functionality of OpenCV. Specifically, a specially crafted JSON file could cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. A remote attacker could exploit this flaw by providing a specially crafted JSON file to trigger this vulnerability.
Debian
CVE-2019-5064: opencv - An exploitable heap buffer overflow vulnerability exists in the data structure p...
vendor_debian·2019·CVSS 8.8
CVE-2019-5064 [HIGH] CVE-2019-5064: opencv - An exploitable heap buffer overflow vulnerability exists in the data structure p...
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 4.2.0+dfsg-3)
bullseye: resolved (fixed in 4.2.0+dfsg-3)
forky: resolved (fixed in 4.2.0+dfsg-3)
sid: resolved (fixed in 4.2.0+dfsg-3)
trixie: resolved (fixed in 4.2.0+dfsg-3)
OSV
Out-of-bounds Write in OpenCV
osv·2021-10-12
CVE-2019-5064 [HIGH] Out-of-bounds Write in OpenCV
Out-of-bounds Write in OpenCV
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0 (corresponds with OpenCV-Python version 4.1.2.30). A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
GHSA
Out-of-bounds Write in OpenCV
ghsa·2021-10-12
CVE-2019-5064 [HIGH] CWE-120 Out-of-bounds Write in OpenCV
Out-of-bounds Write in OpenCV
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0 (corresponds with OpenCV-Python version 4.1.2.30). A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
OSV
CVE-2019-5064: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4
osv·2020-01-03·CVSS 8.8
CVE-2019-5064 [HIGH] CVE-2019-5064: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
blogs_talos·2020-01-02·CVSS 8.8
[HIGH] Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
## Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
Dave McDaniel of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered two buffer overflow vulnerabilities in the OpenCV libraries. An attacker could potentially exploit these bugs to cause heap corruptions and potentially code execution. Intel Research originally developed OpenCV in 1999, but it is currently maintained by the non-profit organization OpenCV.org.
OpenCV is used for numerous applications, including facial recognition technology, robotics, motion tracking and various machine learning programs. In accordance with our coordinated disclosure policy, Cisco Talos worked with OpenCV to ensure that these issues are resolved and that an update is available for affected customers.
##
Talos
Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
blogs_talos·2020-01-02·CVSS 8.8
[HIGH] Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV
Dave McDaniel of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered two buffer overflow vulnerabilities in the OpenCV libraries. An attacker could potentially exploit these bugs to cause heap corruptions and potentially code execution. Intel Research originally developed OpenCV in 1999, but it is currently maintained by the non-profit organization OpenCV.org.
OpenCV is used for numerous applications, including facial recognition technology, robotics, motion tracking and various machine learning programs.
In accordance with our coordinated disclosure policy, Cisco Talos worked with OpenCV to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability detailsOpenCV XML persistence parser buffer overflow vulnerab
Bugzilla
CVE-2019-5064 opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file
bugzilla·2020-01-11·CVSS 8.8
CVE-2019-5064 [HIGH] CVE-2019-5064 opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file
CVE-2019-5064 opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
References:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0853
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1790060]
---
External References:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0853
---
Mitigation:
Avoid loading OpenCV data structures from external untrusted JSON fi
Bugzilla
CVE-2019-5064 opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file [fedora-all]
bugzilla·2020-01-11·CVSS 8.8
CVE-2019-5064 [HIGH] CVE-2019-5064 opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file [fedora-all]
CVE-2019-5064 opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
https://github.com/opencv/opencv/issues/15857https://talosintelligence.com/vulnerability_reports/TALOS-2019-0853https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://github.com/opencv/opencv/issues/15857https://talosintelligence.com/vulnerability_reports/TALOS-2019-0853https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.html
2020-01-03
Published