CVE-2017-12597: High severity OpenCV Opencv vulnerability
Published Aug 7, 2017
·Updated
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread.
Affected Software
3 affected components
OpenCV Opencv<=3.3.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Aug 7, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12597?
CVE-2017-12597 is rated as a high severity vulnerability due to its potential for causing out-of-bounds write errors.
2
How do I fix CVE-2017-12597?
To fix CVE-2017-12597, upgrade OpenCV to version 3.4 or later where the vulnerability has been addressed.
3
Which versions of OpenCV are affected by CVE-2017-12597?
CVE-2017-12597 affects OpenCV versions up to and including 3.3.0.
4
What is the nature of the vulnerability in CVE-2017-12597?
CVE-2017-12597 is caused by an out-of-bounds write error in the FillColorRow1 function while reading image files.
5
On which operating systems does CVE-2017-12597 affect OpenCV?
CVE-2017-12597 affects OpenCV on Debian GNU/Linux versions 8.0 and 9.0.