CVE-2017-12603: Debian Linux
High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.
OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 2-opencv-heapoverflow-fseek test case.
Affected products
Published 2017-08-07. Last modified 2026-06-17.