Back

HIGH

opencv: Heap buffer overflow in persistence_json.cpp while parsing crafted JSON file

Published Jan 3, 2020

Description

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

Affected products

Remediation

Red Hat statement

This flaw did not affect the versions of OpenCV as shipped with Red Hat Enterprise Linux 6, 7, and 8, as they did not include the vulnerable code, which was introduced in a later version of the library.

Red Hat mitigation

Avoid loading OpenCV data structures from external untrusted JSON files.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Jan 3, 2020
Updated Aug 4, 2024
Reserved Jan 4, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 2, 2020
GHSA-Q799-Q27X-VP7W