First published: Mon Sep 04 2017(Updated: )
OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12597.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenCV | =3.3.0 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14136 has a high severity rating due to the potential for exploitation via out-of-bounds write errors.
To fix CVE-2017-14136, update OpenCV to a version higher than 3.3.0 that addresses this vulnerability.
CVE-2017-14136 affects OpenCV version 3.3.0 and Debian GNU/Linux 8.0.
Exploitation of CVE-2017-14136 can lead to corruption of memory, system crashes, or execution of arbitrary code.
CVE-2017-14136 was disclosed in August 2017.