Junglewise Threat Intelligence

CVE-2017-12598: PYSEC-2026-698 - Out-of-bounds Read in OpenCV

CVE-2017-12598 · Severity: low · CVSS 3 · Published 2026-07-02

Technologies: opencv-contrib-python (PyPI), opencv-python (PyPI). Vendors: PyPI, OpenCV.

Executive brief

OpenCV is a widely-used library for computer vision and image processing. An out-of-bounds read vulnerability in the image file parsing function allows attackers to crash applications or potentially read sensitive memory by providing a specially-crafted image file. Applications using OpenCV to load untrusted images are at risk of denial of service.

Technical details

An out-of-bounds read vulnerability exists in OpenCV's cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when processing image files via cv::imread. The vulnerability is triggered by a malformed or specially-crafted image file that causes the function to read memory beyond allocated buffer boundaries (CWE-125). The attack requires no authentication and only needs user interaction to open a malicious image file; no network access is required beyond delivery of the image. An attacker can trigger a crash (denial of service) and potentially disclose heap memory contents. The fix is available in opencv-python version 3.3.1.11 and later.

Affected products

  • OpenCV opencv-python through 3.3.0.9
  • OpenCV opencv-contrib-python through 3.3.0.9

Timeline

  • 2017-08-07: disclosed: Published on NVD
  • 2021-10-12: other: Advisory published on GitHub Security Advisory

References

Related threats