Heap Buffer Overflow Vulnerability in OpenCV by OpenCV Foundation
CVE-2019-5064
8.8HIGH
What is CVE-2019-5064?
A heap buffer overflow vulnerability affects OpenCV prior to version 4.2.0, through its data structure persistence feature. Attackers may exploit this flaw by supplying a specially crafted JSON file that leads to a buffer overflow, causing multiple heap corruption issues. This potentially enables the execution of arbitrary code, posing significant security risks for applications utilizing affected OpenCV versions.
Affected Version(s)
OpenCV OpenCV 4.1.0
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
