opencv-python-headless is vulnerable to Heap-based Buffer Overflow
95
Critical Risk
Affected versions of the opencv-python-headless library are vulnerable to heap-based buffer overflow. It allows a remote attacker to perform an out-of-bounds memory write via a crafted WebP file.
You are affected if you are using a version that falls within the vulnerable range. This is only exploitable if 'the color_cache_bits' value defines which size of the HuffmanCode buffer to use.
opencv-python-headless is vulnerable to Heap-based Buffer Overflow in versions 3.1.0.0 - 4.8.1.76.
Upgrade the opencv-python-headless library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant