USN-7247-1: OpenCV vulnerabilities
It was discovered that OpenCV did not properly manage certain XML data, leading to a NULL pointer dereference. If a user were tricked into loading a specially crafted file, a remote attacker could possibly use this issue to make OpenCV crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-14493) It was discovered that OpenCV may perform out-of-bounds reads in certain situations. An attacker could possibly use this issue to cause OpenCV to crash, resulting in a denial of service, or the execution of arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-16249, CVE-2019-19624) It was discovered that the QR code module of OpenCV incorrectly processed certain maliciously crafted QR codes. A remote attacker could possibly use this issue to cause OpenCV to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-2617, CVE-2023-2618)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7247-1?
USN-7247-1 is classified as a denial of service vulnerability due to NULL pointer dereference in OpenCV.
How do I fix USN-7247-1?
To fix USN-7247-1, users should update to the patched version 4.5.4+dfsg-9ubuntu4+esm1 for Ubuntu 22.04 or 3.2.0+dfsg-4ubuntu0.1+esm4 for Ubuntu 18.04.
Which versions of OpenCV are affected by USN-7247-1?
Affected versions in USN-7247-1 include OpenCV versions prior to 4.5.4+dfsg-9ubuntu4+esm1 for Ubuntu 22.04 and 3.2.0+dfsg-4ubuntu0.1+esm4 for Ubuntu 18.04.
What could happen if I do not address USN-7247-1?
If not addressed, USN-7247-1 could lead to application crashes, causing a denial of service for users relying on OpenCV.
What components of OpenCV are impacted by USN-7247-1?
USN-7247-1 impacts several OpenCV components such as libopencv-core, libopencv-contrib, and libopencv-dev, among others.