CVE-2019-5064
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 10.70% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120, CWE-787
- Affected
- opencv/opencv · oracle/application testing suite · oracle/big data spatial and graph · oracle/enterprise manager base platform
- Source
- talos-cna@cisco.com
References
- https://github.com/opencv/opencv/issues/15857Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0853Exploit, Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://github.com/opencv/opencv/issues/15857Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0853Exploit, Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.