Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
- Snyk ID SNYK-PYTHON-OPENCVPYTHON-1731320
- published 13 Oct 2021
- disclosed 12 Oct 2021
- credit Unknown
How to fix?
opencv-python to version 18.104.22.168 or higher.
opencv-python is a Wrapper package for OpenCV python bindings.
Affected versions of this package are vulnerable to Buffer Overflow via the data structure persistence functionality of
OpenCV. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.