CVE-2017-18009: High severity opencv vulnerability
Published Jan 1, 2018
·Updated
In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmthdr.cpp.
Affected Software
3 affected componentsFixes available
OpenCV Opencv=3.3.1
debian/opencv
4.5.1+dfsg-54.6.0+dfsg-124.6.0+dfsg-144.10.0+dfsg-2
Google Android
Event History
Jan 1, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Feb 16, 2025
Data Sourced
via Ubuntu·04:13 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·04:15 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18009?
CVE-2017-18009 is a vulnerability in OpenCV 3.3.1 that allows a heap-based buffer over-read.
2
How severe is CVE-2017-18009?
CVE-2017-18009 has a severity rating of 7.5 (high).
3
Which software versions are affected by CVE-2017-18009?
OpenCV 3.3.1 is affected by CVE-2017-18009.
4
How can I fix CVE-2017-18009?
To fix CVE-2017-18009, update to a version of OpenCV that is not affected by the vulnerability.
5
Where can I find more information about CVE-2017-18009?
You can find more information about CVE-2017-18009 in the references provided: [link1](https://source.android.com/docs/security/bulletin/2019-02-01/#asterisk), [link2](https://source.android.com/docs/security/bulletin/2019-02-01), [link3](http://www.securityfocus.com/bid/106945).