In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Struktur
Struktur libheif |
|
Weaknesses | CWE-125 CWE-787 |
|
CPEs | cpe:2.3:a:struktur:libheif:1.17.6:*:*:*:*:*:*:* | |
Vendors & Products |
Struktur
Struktur libheif |
|
Metrics |
cvssV3_1
|
Tue, 15 Oct 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-15T00:00:00
Updated: 2024-10-23T00:10:12.649Z
Reserved: 2024-07-18T00:00:00
Link: CVE-2024-41311
Vulnrichment
Updated: 2024-10-23T00:10:12.649Z
NVD
Status : Awaiting Analysis
Published: 2024-10-15T21:15:10.923
Modified: 2024-10-16T19:35:06.653
Link: CVE-2024-41311
Redhat
No data.