CVE-2020-19499: High severity libheif vulnerability
Published Jul 21, 2021
·Updated
An issue was discovered in heif::Boxiref::getreferences in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.
Affected Software
1 affected component
struktur Libheif=1.4.0
Remediation
Event History
Jul 21, 2021
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-19499.
2
What is the severity of CVE-2020-19499?
The severity of CVE-2020-19499 is high with a severity value of 8.8.
3
What is the affected software?
The affected software is Struktur Libheif version 1.4.0.
4
How can attackers exploit CVE-2020-19499?
Attackers can exploit CVE-2020-19499 to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.
5
Is there a fix available for CVE-2020-19499?
Yes, a fix is available. It is recommended to update to a version of libheif that is not affected by the vulnerability.