CVE-2019-14491

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
opencvopencv
𝑥
< 3.4.7
opencvopencv
4.0.0 ≤
𝑥
< 4.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
opencv
bookworm
4.6.0+dfsg-12
fixed
bullseye
4.5.1+dfsg-5
fixed
buster
no-dsa
jessie
postponed
sid
4.6.0+dfsg-14
fixed
stretch
no-dsa
trixie
4.6.0+dfsg-14
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opencv
bionic
Fixed 3.2.0+dfsg-4ubuntu0.1+esm2
released
disco
ignored
eoan
ignored
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
trusty
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libopencv3_3
suse enterprise desktop 15
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP1
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP2
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP3
3.3.1-6.6.1
fixed
suse enterprise sap 15
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP1
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP2
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP3
3.3.1-6.6.1
fixed
suse enterprise server 15
3.3.1-6.6.1
fixed
suse enterprise server 15 SP1
3.3.1-6.6.1
fixed
suse enterprise server 15 SP2
3.3.1-6.6.1
fixed
suse enterprise server 15 SP3
3.3.1-6.6.1
fixed
suse enterprise workstation 15
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP1
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP2
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP3
3.3.1-6.6.1
fixed
libopencv3_4
suse enterprise desktop 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise sap 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise server 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise workstation 15 SP4
3.4.16-150400.1.9
fixed
libopencv405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_aruco405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_face405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_highgui405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_imgcodecs405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_objdetect405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_superres405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_videoio405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_videostab405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
libopencv_ximgproc405
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
opencv
suse enterprise desktop 15
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP1
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP2
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP3
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP1
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP2
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP3
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15
3.3.1-6.6.1
fixed
suse enterprise server 15 SP1
3.3.1-6.6.1
fixed
suse enterprise server 15 SP2
3.3.1-6.6.1
fixed
suse enterprise server 15 SP3
3.3.1-6.6.1
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP1
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP2
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP3
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
opencv-devel
suse enterprise desktop 15
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP1
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP2
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP3
3.3.1-6.6.1
fixed
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP1
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP2
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP3
3.3.1-6.6.1
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15
3.3.1-6.6.1
fixed
suse enterprise server 15 SP1
3.3.1-6.6.1
fixed
suse enterprise server 15 SP2
3.3.1-6.6.1
fixed
suse enterprise server 15 SP3
3.3.1-6.6.1
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP1
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP2
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP3
3.3.1-6.6.1
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed
opencv3
suse enterprise desktop 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise sap 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise server 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise workstation 15 SP4
3.4.16-150400.1.9
fixed
opencv3-devel
suse enterprise desktop 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise sap 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise server 15 SP4
3.4.16-150400.1.9
fixed
suse enterprise workstation 15 SP4
3.4.16-150400.1.9
fixed
opencv4-cascades-data
suse enterprise desktop 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise sap 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise server 15 SP4
4.5.5-150400.1.28
fixed
suse enterprise workstation 15 SP4
4.5.5-150400.1.28
fixed