CVE-2019-9423 PUBLISHED

In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616

EPSS 0.03% · 8.6th percentile

Risk Scores

EPSS Score
0.03%
8.6th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSopencv4.1.2+dfsg-4ubuntu3, 3.2.0+dfsg-6build2, 0
Ubuntu:Pro:14.04:LTSopencv0, 2.4.5+dfsg-0ubuntu4, 2.4.5+dfsg-0ubuntu5
Ubuntu:Pro:16.04:LTSopencv2.4.9.1+dfsg-1.5ubuntu1, 2.4.9.1+dfsg-1.5ubuntu1.1+esm1, 0
Ubuntu:Pro:18.04:LTSopencv3.2.0+dfsg-4ubuntu0.1+esm3, 0, 3.1.0+dfsg1-1~exp1ubuntu3
Ubuntu:Pro:22.04:LTSopencv0, 4.5.4+dfsg-9ubuntu4+esm1, 4.5.4+dfsg-9ubuntu4
Ubuntu:25.10opencv4.10.0+dfsg-5ubuntu1, 0, 4.10.0+dfsg-5
Ubuntu:24.04:LTSopencv4.6.0+dfsg-13build5, 4.6.0+dfsg-13.1build2, 4.6.0+dfsg-13.1ubuntu1

Timeline

References

Open in Interactive Console →