Bug 2176471 - libheif: crafted image file causing buffer overflow in linear memory
Summary: libheif: crafted image file causing buffer overflow in linear memory
Keywords:
Status: NEW
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2173146
TreeView+ depends on / blocked
 
Reported: 2023-03-08 13:20 UTC by juneau
Modified: 2023-07-07 08:27 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description juneau 2023-03-08 13:20:34 UTC
CVE-2023-0996
There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

https://govtech-csg.github.io/security-advisories/2023/02/24/CVE-2023-0996.html
https://github.com/strukturag/libheif/pull/759


Note You need to log in before you can comment on or make changes to this bug.