CVE-2020-23109: Buffer Overflow
Published Nov 3, 2021
·Updated
Buffer overflow vulnerability in function convertcolorspace in heifcolorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.
Affected Software
2 affected componentsFixes available
debian/libheif
1.11.0-11.15.1-11.18.1-2
struktur Libheif=1.6.2
Event History
Nov 3, 2021
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
Description
Jun 26, 2024
Data Sourced
via Launchpad·09:46 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·10:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-23109?
CVE-2020-23109 is a buffer overflow vulnerability in the function convert_colorspace in libheif v1.6.2.
2
What is the severity of CVE-2020-23109?
The severity of CVE-2020-23109 is 8.1 (high).
3
What is the affected software?
The affected software is Struktur Libheif v1.6.2.
4
How can attackers exploit CVE-2020-23109?
Attackers can exploit CVE-2020-23109 by using a crafted HEIF file to cause a denial of service and disclose sensitive information.
5
Is there a fix available for CVE-2020-23109?
Yes, a fix is available for CVE-2020-23109. It is recommended to update to the latest version of Struktur Libheif.