First published: Wed Nov 03 2021(Updated: )
Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Struktur Libheif | =1.6.2 | |
debian/libheif | 1.11.0-1 1.15.1-1 1.18.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23109 is a buffer overflow vulnerability in the function convert_colorspace in libheif v1.6.2.
The severity of CVE-2020-23109 is 8.1 (high).
The affected software is Struktur Libheif v1.6.2.
Attackers can exploit CVE-2020-23109 by using a crafted HEIF file to cause a denial of service and disclose sensitive information.
Yes, a fix is available for CVE-2020-23109. It is recommended to update to the latest version of Struktur Libheif.