CVE-2017-1000450

Description

In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.264

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-opencv-contrib-python 3.3.1.11Windows
Multiple vulnerabilities are fixed in Python-opencv-python 3.3.1.11Windows
Multiple vulnerabilities are fixed in Python-opencv-contrib-python for linux 3.3.1.11Linux
Multiple vulnerabilities are fixed in Python-opencv-python for linux 3.3.1.11Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234