In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
References
Link Resource
https://github.com/opencv/opencv/issues/9372 Issue Tracking Patch Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00030.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/10/msg00028.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201712-02 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-08-15T16:00:00

Updated: 2021-10-30T21:06:28

Reserved: 2017-08-15T00:00:00


Link: CVE-2017-12864

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-08-15T16:29:00.340

Modified: 2021-11-30T22:05:59.273


Link: CVE-2017-12864

JSON object: View

cve-icon Redhat Information

No data.

CWE