CVE-2017-14136: Medium severity opencv vulnerability
Published Sep 4, 2017
·Updated
OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12597.
Affected Software
2 affected components
OpenCV Opencv=3.3.0
Debian Debian Linux=8.0
Remediation
Patch Available
Patch Available
Event History
Sep 4, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14136?
CVE-2017-14136 has a high severity rating due to the potential for exploitation via out-of-bounds write errors.
2
How do I fix CVE-2017-14136?
To fix CVE-2017-14136, update OpenCV to a version higher than 3.3.0 that addresses this vulnerability.
3
What software is affected by CVE-2017-14136?
CVE-2017-14136 affects OpenCV version 3.3.0 and Debian GNU/Linux 8.0.
4
What risks are associated with CVE-2017-14136?
Exploitation of CVE-2017-14136 can lead to corruption of memory, system crashes, or execution of arbitrary code.
5
When was CVE-2017-14136 disclosed?
CVE-2017-14136 was disclosed in August 2017.