Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 7 MGASA-2020-0030 Moderate: Opencv Out Of Bounds Access

mageia
Calendar Grey January 11, 2020
Dist Mageia Esm H88
Recent updates for opencv packages in Mageia tackle significant security threats, rectifying severe problems related to out-of-bounds accesses.
The updated packages fix security vulnerabilities: An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1

Summary

The updated packages fix security vulnerabilities:
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service. (CVE-2019-14491)
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator:: OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service. (CVE-2019-14492)
An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modules/objdetect/src/hog.cpp. (CVE-2019-15939)

References

- https://bugs.mageia.org/show_bug.cgi?id=25855

- https://lists.suse.com/pipermail/sle-security-updates/2019-December/006214.html

- - https://www.cve.org/CVERecord?id=CVE-2019-14491

- https://www.cve.org/CVERecord?id=CVE-2019-14492

- https://www.cve.org/CVERecord?id=CVE-2019-15939

Resolution

SRPMS

- 7/core/opencv-3.4.5-2.1.mga7

Publication date: 11 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0030.html
Type: security
CVE: CVE-2019-14491, CVE-2019-14492, CVE-2019-15939

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here