CVE-2021-32287: High severity nokia heif vulnerability
Published Sep 20, 2021
·Updated
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
Affected Software
1 affected component
Nokia Heif<=3.6.2
Event History
Sep 20, 2021
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-32287.
2
What is the severity of CVE-2021-32287?
The severity of CVE-2021-32287 is high.
3
What is the affected software?
The affected software is Nokia Heif (version up to and including 3.6.2).
4
What is the description of CVE-2021-32287?
CVE-2021-32287 is a global-buffer-overflow vulnerability in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code execution.
5
How can I fix the vulnerability in Nokia Heif?
To fix the vulnerability in Nokia Heif, update to version 3.6.3 or later.