CVE-2017-12606: High severity OpenCV Opencv vulnerability
Published Aug 7, 2017
·Updated
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow4 in utils.cpp when reading an image file by using cv::imread.
Affected Software
3 affected components
OpenCV Opencv<=3.3.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Aug 7, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12606?
CVE-2017-12606 has been classified as a high-severity vulnerability due to the potential for out-of-bounds write errors.
2
How do I fix CVE-2017-12606?
To fix CVE-2017-12606, update OpenCV to a version later than 3.3.0 that addresses this vulnerability.
3
Which versions of OpenCV are affected by CVE-2017-12606?
CVE-2017-12606 affects all OpenCV versions up to and including 3.3.0.
4
How does CVE-2017-12606 affect Debian systems?
CVE-2017-12606 affects Debian versions 8.0 and 9.0 that utilize the vulnerable OpenCV library.
5
What type of error does CVE-2017-12606 cause in OpenCV?
CVE-2017-12606 results in an out-of-bounds write error in the FillColorRow4 function when processing image files.