CVE-2023-0996: Buffer Overflow
Last updated 24 July 2024
Other sources
There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability CVE-2023-0996?
CVE-2023-0996 is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif.
How severe is CVE-2023-0996?
CVE-2023-0996 has a severity level of 7.8, which is considered high.
What software is affected by CVE-2023-0996?
The Struktur Libheif version 1.14.2 is affected by CVE-2023-0996.
How can an attacker exploit CVE-2023-0996?
An attacker can exploit CVE-2023-0996 through a crafted image file to cause a buffer overflow during a memcpy call.
Are there any references for CVE-2023-0996?
Yes, you can find references for CVE-2023-0996 at the following links: - [GitHub Pull Request](https://github.com/strukturag/libheif/pull/759) - [Security Advisories](https://govtech-csg.github.io/security-advisories/2023/02/24/CVE-2023-0996.html)