CVE-2020-19498: High severity libheif vulnerability
Published Jul 21, 2021
·Updated
Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
Affected Software
1 affected component
struktur Libheif=1.4.0
Remediation
Event History
Jul 21, 2021
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What is CVE-2020-19498?
CVE-2020-19498 is a vulnerability in libheif 1.4.0 that allows attackers to cause a Denial of Service or possibly other unspecified impacts.
2
What is the severity of CVE-2020-19498?
The severity of CVE-2020-19498 is high, with a CVSS score of 8.8.
3
How can attackers exploit CVE-2020-19498?
Attackers can exploit CVE-2020-19498 by causing a Floating Point Exception in the Fraction function of libheif 1.4.0.
4
What is the affected software version of CVE-2020-19498?
The affected software version of CVE-2020-19498 is libheif 1.4.0.
5
Is there a fix for CVE-2020-19498?
Yes, a fix for CVE-2020-19498 is available in the Struktur Libheif repository.