{"id":"UBUNTU-CVE-2023-2618","details":"A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this issue is the function DecodedBitStreamParser::decodeHanziSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to memory leak. The attack may be launched remotely. The name of the patch is 2b62ff6181163eea029ed1cab11363b4996e9cd6. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-228548.","modified":"2026-04-22T14:04:02.604968Z","published":"2023-05-10T06:15:00Z","related":["USN-7247-1"],"upstream":["CVE-2023-2618"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-2618"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-2618"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7247-1"}],"affected":[{"package":{"name":"opencv","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/opencv@4.5.4+dfsg-9ubuntu4+esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.4+dfsg-9ubuntu4+esm1"}]}],"versions":["4.5.3+dfsg-1ubuntu1","4.5.4+dfsg-9ubuntu2","4.5.4+dfsg-9ubuntu4"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"libopencv-calib3d4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-contrib4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-core4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-dnn4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-features2d4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-flann4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-highgui4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-imgcodecs4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-imgproc4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-ml4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_version":"4.5.4+dfsg-9ubuntu4+esm1","binary_name":"libopencv-objdetect4.5d"},{"binary_name":"libopencv-photo4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-shape4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-stitching4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-superres4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-video4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-videoio4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-videostab4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv-viz4.5d","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv4.5-java","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"libopencv4.5d-jni","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_name":"opencv-data","binary_version":"4.5.4+dfsg-9ubuntu4+esm1"},{"binary_version":"4.5.4+dfsg-9ubuntu4+esm1","binary_name":"python3-opencv"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-2618.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}