First published: Mon Jan 01 2018(Updated: )
In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opencv Opencv | =3.3.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18009 is a vulnerability in OpenCV 3.3.1 that allows a heap-based buffer over-read.
CVE-2017-18009 has a severity rating of 7.5 (high).
OpenCV 3.3.1 is affected by CVE-2017-18009.
To fix CVE-2017-18009, update to a version of OpenCV that is not affected by the vulnerability.
You can find more information about CVE-2017-18009 in the references provided: [link1](https://source.android.com/docs/security/bulletin/2019-02-01/#asterisk), [link2](https://source.android.com/docs/security/bulletin/2019-02-01), [link3](http://www.securityfocus.com/bid/106945).