
Publication date 15 August 2017

Last updated 24 July 2024

Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

From the Ubuntu Security Team

It was discovered that OpenCV incorrectly handled certain image files. An attacker could possibly use this issue to cause a denial of service, execute arbitrary code or other unspecified impact.


Package Ubuntu Release Status
opencv 18.04 LTS bionic
Fixed 3.2.0+dfsg-4ubuntu0.1
17.10 artful Ignored end of life
17.04 zesty Ignored end of life
16.04 LTS xenial
14.04 LTS trusty
Fixed 2.4.8+dfsg1-2ubuntu1.1

Severity score breakdown

Parameter Value
Base score 8.8 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H