Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Debian Wheezy DLA-1354-1 Critical: OpenCV Buffer Issues

debian lts
Calendar Grey April 18, 2018
Dist Debian Esm H88
Enhance OpenCV libraries to resolve serious concerns stemming from two vulnerabilities associated with buffer overruns and assertion errors.
Two vulnerabilities were found in OpenCV, the "Open Computer Vision Library"

Summary

In OpenCV 3.3.1, a heap-based buffer overflow happens in
cv::Jpeg2KDecoder::readComponent8u in
modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted
image file.

CVE-2018-5269

In OpenCV 3.3.1, an assertion failure happens in
cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp
because of an incorrect integer cast.

For Debian 7 "Wheezy", these problems have been fixed in version
2.3.1-11+deb7u4.

We recommend that you upgrade your opencv packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: opencv
Version: 2.3.1-11+deb7u4
CVE ID: CVE-2018-5268 CVE-2018-5269
Debian Bug: 886674 886675

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here