There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libheif | Jul 30, 2024 | Feb 24, 2023 |
| Suse | — | Upgrade gdk-pixbuf-loader-libheifUpgrade libheif-develUpgrade libheif1-32bitUpgrade libheif1 | Apr 6, 2023 | Feb 24, 2023 |
| Ubuntu | — | Upgrade libheif1Upgrade libheif-dev (Ubuntu Pro)Upgrade libheif1 (Ubuntu Pro)Upgrade libheif-plugin-libde265Upgrade heif-gdk-pixbufUpgrade libheif-devUpgrade heif-gdk-pixbuf (Ubuntu Pro) | Jul 1, 2024 | Feb 24, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub