CVE-2017-12864: Integer Overflow
Published Aug 15, 2017
·Updated
In opencv/modules/imgcodecs/src/grfmtpxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Affected Software
3 affected components
OpenCV Opencv<=3.3.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Aug 15, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12864?
CVE-2017-12864 has a high severity rating due to its potential for remote code execution or denial of service.
2
How do I fix CVE-2017-12864?
To fix CVE-2017-12864, update to OpenCV version 3.4.0 or later.
3
Which versions of OpenCV are affected by CVE-2017-12864?
CVE-2017-12864 affects OpenCV versions 3.3.0 and earlier.
4
Can CVE-2017-12864 lead to remote code execution?
Yes, CVE-2017-12864 can lead to remote code execution if exploited through a specially crafted image.
5
What types of software does CVE-2017-12864 impact?
CVE-2017-12864 impacts OpenCV as well as Debian GNU/Linux versions 8.0 and 9.0.