CVE-2019-9423

Published: 27 September 2019

In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
opencv
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 20.10 (Groovy Gorilla) Deferred
(2020-03-09)
Ubuntu 20.04 LTS (Focal Fossa) Deferred
(2020-03-09)
Ubuntu 18.04 LTS (Bionic Beaver) Deferred
(2020-03-09)
Ubuntu 16.04 LTS (Xenial Xerus) Deferred
(2020-03-09)
Ubuntu 14.04 ESM (Trusty Tahr) Deferred
(2020-03-09)