Logo
vulnerabilityCVE-2023-2618
Name
CVE-2023-2618
Source
NVD ( link)Debian ( link)
Description
A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this issue is the function DecodedBitStreamParser::decodeHanziSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to memory leak. The attack may be launched remotely. The name of the patch is 2b62ff6181163eea029ed1cab11363b4996e9cd6. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-228548.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
opencv
Patched

Vulnerability Ratings#


5.3
CVSSv31
7.5
CVSSv31
5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.4.19
Not Affected
buildroot
2025.02.x
4.12.0
Not Affected
buildroot
master
4.13.0
Not Affected
yocto
master
4.13.0
Not Affected
yocto
scarthgap
4.9.0
Not Affected

Resolved with patches#


opencv (yocto:kirkstone)

#
Title
Author
Resolve
1
fix(wechat_qrcode): fixed memory leaks
Nano <nanoapezlk@gmail.com>
CVE-2023-2618