Skip to content

Add assert to address tf simplifier security concerns#21861

Merged
opencv-pushbot merged 1 commit intoopencv:3.4from
rogday:21852_fix
Apr 14, 2022
Merged

Add assert to address tf simplifier security concerns#21861
opencv-pushbot merged 1 commit intoopencv:3.4from
rogday:21852_fix

Conversation

@rogday
Copy link
Copy Markdown
Member

@rogday rogday commented Apr 13, 2022

Merge with extra: opencv/opencv_extra#970
Fixes #21852

Another way of fixing this is to draw inspiration from Rust: use custom vector type with bound checks enabled by default, providing methods that don't do bounds-checking.

Pull Request Readiness Checklist

See details at https://github.com/opencv/opencv/wiki/How_to_contribute#making-a-good-pull-request

  • I agree to contribute to the project under Apache 2 License.
  • To the best of my knowledge, the proposed patch is not based on a code under GPL or another license that is incompatible with OpenCV
  • The PR is proposed to the proper branch
  • There is a reference to the original bug report and related work
  • There is accuracy test, performance test and test data in opencv_extra repository, if applicable
    Patch to opencv_extra has the same branch name.
  • The feature is well documented and sample code can be built with the project CMake

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

readNetFromTensorflow: BufferOverflow

3 participants