CVE-2017-17760 describes a buffer overflow vulnerability in OpenCV version 3.3.1, specifically within the cv::PxMDecoder::readData function, due to an incorrect size value being used. This flaw primarily impacts Debian Linux distributions utilizing OpenCV. With a CVSS score of 6.5 (Medium), it can be triggered remotely through user interaction and lead to high availability impact, though confidentiality and integrity are not directly affected. While the vulnerability has garnered some community discussion and media coverage, there is currently no evidence of active exploitation, nor are there publicly available exploit modules like Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.1CPE matchmatch criteria | cpe:2.3:a:opencv:opencv:3.3.1:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.