CVE-2017-12599: High severity OpenCV Opencv vulnerability
Published Aug 7, 2017
·Updated
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvtBGRA2BGR8uC4C3R when reading an image file by using cv::imread.
Affected Software
3 affected components
OpenCV Opencv<=3.3.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Aug 7, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12599?
CVE-2017-12599 has a high severity due to its potential to cause out-of-bounds read errors, which can lead to information disclosure.
2
How does CVE-2017-12599 affect OpenCV versions?
CVE-2017-12599 affects OpenCV versions up to and including 3.3.0.
3
What is the impact of CVE-2017-12599 on image processing?
CVE-2017-12599 can lead to application crashes or unexpected behavior when processing certain image files.
4
How can users mitigate CVE-2017-12599?
Users can mitigate CVE-2017-12599 by upgrading to OpenCV version 3.4.0 or later where the vulnerability is fixed.
5
Which operating systems are affected by CVE-2017-12599?
CVE-2017-12599 affects Debian GNU/Linux versions 8.0 and 9.0 that utilize vulnerable OpenCV libraries.