An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-calib3d-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-calib3d4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-calib3d4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-contrib-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-contrib4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-contrib4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-core-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-core4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-core4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-dev-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-dnn-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-dnn4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-dnn4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-features2d-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-features2d4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-features2d4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-flann-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-flann4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-flann4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-highgui-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-highgui4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-highgui4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-imgcodecs-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-imgcodecs4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-imgcodecs4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-imgproc-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-imgproc4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-imgproc4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-ml-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-ml4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-ml4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-objdetect-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-objdetect4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-objdetect4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-photo-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-photo4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-photo4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-shape-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-shape4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-shape4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-stitching-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-stitching4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-stitching4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-superres-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-superres4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-superres4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-ts-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-video-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-video4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-video4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-videoio-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-videoio4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-videoio4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-videostab-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-videostab4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-videostab4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-viz-dev" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-viz4.2" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv-viz4.2-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv4.2-java" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv4.2-jni" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "libopencv4.2-jni-dbgsym" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "opencv-data" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "opencv-doc" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "python3-opencv" }, { "binary_version": "4.2.0+dfsg-5", "binary_name": "python3-opencv-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-calib3d-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-calib3d4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-calib3d4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-contrib-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-contrib4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-contrib4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-core-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-core4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-core4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-dev-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-dnn-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-dnn4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-dnn4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-features2d-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-features2d4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-features2d4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-flann-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-flann4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-flann4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-highgui-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-highgui4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-highgui4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-imgcodecs-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-imgcodecs4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-imgcodecs4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-imgproc-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-imgproc4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-imgproc4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-ml-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-ml4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-ml4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-objdetect-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-objdetect4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-objdetect4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-photo-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-photo4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-photo4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-shape-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-shape4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-shape4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-stitching-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-stitching4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-stitching4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-superres-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-superres4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-superres4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-video-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-video4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-video4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-videoio-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-videoio4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-videoio4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-videostab-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-videostab4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-videostab4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-viz-dev" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-viz4.5d" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv-viz4.5d-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv4.5-java" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv4.5d-jni" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "libopencv4.5d-jni-dbgsym" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "opencv-data" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "opencv-doc" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "python3-opencv" }, { "binary_version": "4.5.4+dfsg-9ubuntu4", "binary_name": "python3-opencv-dbgsym" } ] }