CVE-2017-12862: Buffer Overflow
Published Aug 15, 2017
·Updated
In modules/imgcodecs/src/grfmtpxm.cpp, the length of buffer AutoBuffer src is small than expected, which will cause copy buffer overflow later. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Affected Software
3 affected components
OpenCV Opencv<=3.3.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Aug 15, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12862?
CVE-2017-12862 has a high severity due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2017-12862?
To fix CVE-2017-12862, upgrade OpenCV to version 3.4.0 or later.
3
Which versions of OpenCV are affected by CVE-2017-12862?
CVE-2017-12862 affects OpenCV versions 3.3.0 and earlier.
4
Can CVE-2017-12862 lead to data loss?
Yes, if exploited, CVE-2017-12862 can lead to unauthorized memory access, potentially resulting in data loss.
5
Is CVE-2017-12862 specific to any operating system?
CVE-2017-12862 affects OpenCV across multiple operating systems, including Debian GNU/Linux 8.0 and 9.0.