rpm package
opensuse/libheif&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/libheif&distro=openSUSE%20Tumbleweed
Vulnerabilities (22)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-29659 | Med | 6.5 | < 1.19.5-2.1 | 1.19.5-2.1 | May 5, 2023 | A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service. | |
| CVE-2023-0996 | Hig | 7.8 | < 1.19.5-2.1 | 1.19.5-2.1 | Feb 24, 2023 | There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. |
- affected < 1.19.5-2.1fixed 1.19.5-2.1
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.
- affected < 1.19.5-2.1fixed 1.19.5-2.1
There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.
Page 2 of 2