CVE-2017-12864

Description

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.588

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-opencv-contrib-python 3.3.1.11Windows
Multiple vulnerabilities are fixed in Python-opencv-python 3.3.1.11Windows
Multiple vulnerabilities are fixed in Python-opencv-contrib-python for linux 3.3.1.11Linux
Multiple vulnerabilities are fixed in Python-opencv-python for linux 3.3.1.11Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234