First published: Mon Sep 20 2021(Updated: )
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia Heif | <=3.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32288 is a vulnerability discovered in heif software through version 3.6.2, which allows an attacker to cause code execution.
CVE-2021-32288 has a severity score of 7.8 out of 10, indicating a high severity.
The vulnerability affects Nokia Heif software version up to and including 3.6.2.
An attacker can exploit the CVE-2021-32288 vulnerability to perform a global buffer overflow in the HevcDecoderConfigurationRecord::getPicHeight() function, leading to code execution.
You can find more information about CVE-2021-32288 on the following link: https://github.com/nokiatech/heif/issues/87