First published: Mon Aug 07 2017(Updated: )
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an image file by using cv::imread.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenCV | <=3.3.0 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12599 has a high severity due to its potential to cause out-of-bounds read errors, which can lead to information disclosure.
CVE-2017-12599 affects OpenCV versions up to and including 3.3.0.
CVE-2017-12599 can lead to application crashes or unexpected behavior when processing certain image files.
Users can mitigate CVE-2017-12599 by upgrading to OpenCV version 3.4.0 or later where the vulnerability is fixed.
CVE-2017-12599 affects Debian GNU/Linux versions 8.0 and 9.0 that utilize vulnerable OpenCV libraries.