CVE-2021-32288: High severity nokia heif vulnerability
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-32288?
CVE-2021-32288 is a vulnerability discovered in heif software through version 3.6.2, which allows an attacker to cause code execution.
How severe is CVE-2021-32288?
CVE-2021-32288 has a severity score of 7.8 out of 10, indicating a high severity.
What software is affected by CVE-2021-32288?
The vulnerability affects Nokia Heif software version up to and including 3.6.2.
How can an attacker exploit the CVE-2021-32288 vulnerability?
An attacker can exploit the CVE-2021-32288 vulnerability to perform a global buffer overflow in the HevcDecoderConfigurationRecord::getPicHeight() function, leading to code execution.
Where can I find more information about CVE-2021-32288?
You can find more information about CVE-2021-32288 on the following link: https://github.com/nokiatech/heif/issues/87