In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1235-1 opencv security update
Debian DLA Debian DLA DLA-1438-1 opencv security update
Debian DLA Debian DLA DLA-2799-1 opencv security update
EUVD EUVD EUVD-2021-2221 In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
Github GHSA Github GHSA GHSA-m43c-649m-pm48 Integer Overflow or Wraparound in OpenCV.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00811}

epss

{'score': 0.00993}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T22:00:41.401Z

Reserved: 2018-01-02T00:00:00

Link: CVE-2017-1000450

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-02T17:29:00.417

Modified: 2024-11-21T03:04:45.443

Link: CVE-2017-1000450

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-09-26T00:00:00Z

Links: CVE-2017-1000450 - Bugzilla

cve-icon OpenCVE Enrichment

No data.