First published: Thu Aug 01 2019(Updated: )
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opencv Opencv | <3.4.7 | |
Opencv Opencv | >=4.0.0<4.1.1 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-14492 is high, with a CVSS score of 7.5.
CVE-2019-14492 affects OpenCV versions before 3.4.7 and 4.x before 4.1.1.
The vulnerability in CVE-2019-14492 is an out-of-bounds read/write issue in the HaarEvaluator::OptFeature::calc function in modules/objdetect/src/cascadedetect.hpp of OpenCV.
CVE-2019-14492 can be exploited by an attacker to perform a denial-of-service attack.
To fix the vulnerability in CVE-2019-14492, update OpenCV to version 3.4.7 or higher for versions before 4.0.0, or update to version 4.1.1 or higher for versions between 4.0.0 and 4.1.1.