OpenCV»º³åÇøÒç³öÎó²î£¨CVE-2019-5063¡¢CVE-2019-5064£©
Ðû²¼Ê±¼ä 2020-01-05
1.Åä¾°ÐÎò
˼¿ÆTalos×î½üÔÚOpenCV¿âÖз¢Ã÷Á½¸ö»º³åÇøÒç³öÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÀ´µ¼Ö¶ÑË𻵺ÍDZÔڵĴúÂëÖ´ÐС£¡£¡£¡£¡£
2.Îó²îÁбí
CVE ID £º CVE-2019-5063¡¢CVE-2019-5064
Îó²îÆ·¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 8.8
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ó°Ïì¹æÄ££º OpenCV 4.1.0
3.Îó²îÏêÇé
OpenCV£¨¿ªÔ´ÅÌËã»úÊÓ¾õ¿â£©ÊÇÒ»¸öÖ÷ÒªÕë¶ÔʵʱÅÌËã»úÊÓ¾õ±à³Ì¹¦Ð§µÄ¿ªÔ´¿â¡£¡£¡£¡£¡£°üÀ¨Google¡¢Microsoft¡¢Intel¡¢IBM¡¢Yahoo¡¢Sony¡¢Honda¡¢ToyotaºÍÆäËû¹«Ë¾ÔÚÄÚµÄÖ÷Òª¿Æ¼¼¹«Ë¾¶¼Ê¹ÓøÿâÀ´¿ª·¢Ã沿ʶ±ðÊÖÒÕ¡¢»úеÈËÊÖÒÕ¡¢Ô˶¯¸ú×ٵȽâ¾ö¼Æ»®¡£¡£¡£¡£¡£
CVE-2019-5063ºÍCVE-2019-5064¶¼ÊǶѻº³åÇøÒç³öÎó²î£¬£¬£¬£¬±£´æÓÚOpenCV 4.1.0µÄÊý¾Ý½á¹¹³¤ÆÚÐÔ¹¦Ð§ÖС£¡£¡£¡£¡£¸Ã¹¦Ð§ÔÊÐí¿ª·¢Ö°Ô±ÔÚ´ÅÅÌÉϵÄÎļþÖÐдÈëOpenCVÊý¾Ý½á¹¹ÒÔ¼°´Ó´ÅÅÌÉϵÄÎļþÖмìË÷OpenCVÊý¾Ý½á¹¹£¬£¬£¬£¬ÎļþÀàÐÍ¿ÉÒÔÊÇXML¡¢YAML»òJSON¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ»®·Öͨ¹ý¶ñÒâXMLÎļþºÍJSONÎļþ´¥·¢ÕâÁ½¸öÎó²î¡£¡£¡£¡£¡£
CVE-2019-5063Ôڸù¦Ð§ÆÊÎö°üÀ¨Ç±ÔÚ×Ö·ûʵÌåÒýÓõÄXMLÎļþʱ´¥·¢£¬£¬£¬£¬µ±Óöµ½£¦·ûºÅʱ£¬£¬£¬£¬API½«¼ÌÐøÆÊÎö×Ö·û£¬£¬£¬£¬Ö±µ½Óöµ½·ÖºÅΪֹ¡£¡£¡£¡£¡£ÈôÊÇ×Ö·û´®ÓëswitchÓï¾äÖеÄ×Ö·û´®²»Æ¥Å䣬£¬£¬£¬ÔòÊý¾Ý±»ÍêÕû¸´Öƽø»º³åÇøÖС£¡£¡£¡£¡£CVE-2019-5064ÊÇÔڸù¦Ð§ÆÊÎö°üÀ¨¿Õ×Ö½ÚµÄJSONÎļþʱ´¥·¢µÄ£¬£¬£¬£¬µ±Óöµ½¿Õ×Ö½Úʱ£¬£¬£¬£¬Ö±µ½¸ÃµãµÄÕû¸öÖµ¾ù±»¸´Öƽø»º³åÇøÖУ¬£¬£¬£¬µ«API²¢Î´¼ì²éJSONÖµÊÇ·ñ»áÒç³öÄ¿µÄ»º³åÇø¡£¡£¡£¡£¡£
4.ÐÞ¸´½¨Òé
OpenCV 4.2.0°æ±¾ÒѾÐÞ¸´ÁËÕâÁ½¸öÎó²î£¬£¬£¬£¬½¨ÒéÓû§¾ÙÐиüС£¡£¡£¡£¡£
5.²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2020/01/opencv-buffer-overflow-jan-2020.html
https://nvd.nist.gov/vuln/detail/CVE-2019-5063
https://nvd.nist.gov/vuln/detail/CVE-2019-5064
https://securityaffairs.co/wordpress/95962/hacking/opencv-library-buffere-overflow.html