Skip to content

Security Risk: av-4.11.0.86 includes vulnerable libgfortran version (CVE-2014-5044) #1101

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
cx418y opened this issue May 17, 2025 · 0 comments
Assignees

Comments

@cx418y
Copy link

cx418y commented May 17, 2025

Hi maintainers,
I’ve detected that the PyPI package opencv-python-4.11.0.86 includes a binary dependency (opencv_python.libs/libgfortran-91cc3cb1.so.3.0.0), which is vulnerable to CVE-2014-5044.

CVE Details:

Recommended Action:

Please consider upgrade libgfortran to 4.8 or later to mitigate the vulnerability. This will help downstream users avoid potential security issues caused by the bundled vulnerable binary.

Thanks!

@asmorkalov asmorkalov self-assigned this May 23, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants