First published: Tue Aug 15 2017(Updated: )
In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenCV | <=3.3.0 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12864 has a high severity rating due to its potential for remote code execution or denial of service.
To fix CVE-2017-12864, update to OpenCV version 3.4.0 or later.
CVE-2017-12864 affects OpenCV versions 3.3.0 and earlier.
Yes, CVE-2017-12864 can lead to remote code execution if exploited through a specially crafted image.
CVE-2017-12864 impacts OpenCV as well as Debian GNU/Linux versions 8.0 and 9.0.