PT-2023-26735 · Boofcv · Boofcv

·

CVE-2023-39010

·

Published

2023-07-28

·

Updated

2023-10-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BoofCV version 0.42
Description The issue is related to a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability can be exploited by loading a crafted camera calibration file.
Recommendations For BoofCV version 0.42, consider avoiding the use of the boofcv.io.calibration.CalibrationIO.load component until a patch is available. As a temporary workaround, restrict the loading of camera calibration files to trusted sources to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-39010
GHSA-99P5-QPQX-MHWC

Affected Products

Boofcv