Skip to content

Security Risk: av-4.11.0.86 includes vulnerable libgfortran version (CVE-2014-5044) #1101

Open
@cx418y

Description

@cx418y

Hi maintainers,
I’ve detected that the PyPI package opencv-python-4.11.0.86 includes a binary dependency (opencv_python.libs/libgfortran-91cc3cb1.so.3.0.0), which is vulnerable to CVE-2014-5044.

CVE Details:

Recommended Action:

Please consider upgrade libgfortran to 4.8 or later to mitigate the vulnerability. This will help downstream users avoid potential security issues caused by the bundled vulnerable binary.

Thanks!

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions