gyungdal / gyungdal/cSync

CVE-2019-14491 (High) detected in opencv_contrib_python-3.4.3.18-cp36-cp36m-manylinux1_x86_64.whl

Open
#39 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
Python
Stars
2
Forks
3
PR merge metrics
No merged PRs in 30d

Description

## CVE-2019-14491 - High Severity Vulnerability
Vulnerable Library - opencv_contrib_python-3.4.3.18-cp36-cp36m-manylinux1_x86_64.whl

Wrapper package for OpenCV python bindings.


Library home page: https://files.pythonhosted.org/packages/f8/b0/89f8abccea0810b43d25033d6a02dbe81494cd0013a61ce588c0c0d90dd1/opencv_contrib_python-3.4.3.18-cp36-cp36m-manylinux1_x86_64.whl


Path to dependency file: /client/requirements.txt


Path to vulnerable library: /client/requirements.txt


Dependency Hierarchy:
- :x: **opencv_contrib_python-3.4.3.18-cp36-cp36m-manylinux1_x86_64.whl** (Vulnerable Library)

Found in base branch: dev



Vulnerability Details



An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

Publish Date: 2019-08-01

URL: CVE-2019-14491



CVSS 3 Score Details (8.2)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: High


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://github.com/advisories/GHSA-fm39-cw8h-3p63


Release Date: 2019-08-01


Fix Resolution: 3.4.7.28

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with /client/requirements.txt on the dev branch and inspect the pinned opencv_contrib_python dependency. Update it to the stated fixed version, 3.4.7.28, then verify that dependency installation succeeds and the vulnerability is no longer reported.

Written by the indexing model from the issue text.

Assessment

Tech stack
opencv, python
Domain
computer-vision, security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.