Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 647802 (CVE-2018-5268, CVE-2018-5269) - <media-libs/opencv-3.4.1: multiple vulnerabilites (CVE-2018-{5268,5269})
Summary: <media-libs/opencv-3.4.1: multiple vulnerabilites (CVE-2018-{5268,5269})
Status: IN_PROGRESS
Alias: CVE-2018-5268, CVE-2018-5269
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [upstream cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-02-16 00:50 UTC by GLSAMaker/CVETool Bot
Modified: 2020-03-28 21:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2018-02-16 00:50:35 UTC
CVE-2018-5269 (https://nvd.nist.gov/vuln/detail/CVE-2018-5269):
  In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in
  modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.

CVE-2018-5268 (https://nvd.nist.gov/vuln/detail/CVE-2018-5268):
  In OpenCV 3.3.1, a heap-based buffer overflow happens in
  cv::Jpeg2KDecoder::readComponent8u in
  modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
Comment 2 Sam James (sec padawan) 2020-03-28 21:44:07 UTC
(In reply to Amy Liffey from comment #1)
>  - Integrated in opencv 3.4.1 [1] [2]
>  - Not in 2.4.13 -> incoming patch
> 
> [1]
> https://github.com/opencv/opencv/blob/3.4.1/modules/imgcodecs/src/bitstrm.
> cpp#L185
> [2]
> https://github.com/opencv/opencv/blob/3.4.1/modules/imgcodecs/src/
> grfmt_jpeg2000.cpp#L80

So does 2.4.14 need a fix, and does it have one? Thanks!