First published: Mon Mar 05 2018(Updated: )
** DISPUTED ** The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (pixels <= (1<<30)) may be false. Note: “OpenCV CV_Assert is not an assertion (C-like assert()), it is regular C++ exception which can raised in case of invalid or non-supported parameters.”
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opencv Opencv | =3.4.1 | |
=3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7714 is a vulnerability in OpenCV 3.4.1 that allows remote attackers to cause a denial of service.
The CVE-2018-7714 vulnerability can be exploited by sending a specifically crafted input image.
The severity of CVE-2018-7714 is high with a CVSS score of 7.5.
OpenCV 3.4.1 is affected by CVE-2018-7714.
Yes, a fix for CVE-2018-7714 is available. It is recommended to update to the latest version of OpenCV.