CVE-2017-17760 – opencv-contrib-python
Package
Manager: pip
Name: opencv-contrib-python
Vulnerable Version: >=0 <3.4.0.12
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.01394 pctl0.79656
Details
Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV OpenCV 3.3.1 (corresponding with opencv-python and opencv-contrib-python 3.3.1.11) has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.
Metadata
Created: 2021-10-12T22:03:09Z
Modified: 2021-11-18T15:31:01Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-jcxv-2j3h-mg59/GHSA-jcxv-2j3h-mg59.json
CWE IDs: ["CWE-119"]
Alternative ID: GHSA-jcxv-2j3h-mg59
Finding: F316
Auto approve: 1