First published: Fri May 05 2023(Updated: )
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Struktur Libheif | =1.15.1 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
go/github.com/strukturag/libheif | <1.15.2 | 1.15.2 |
debian/libheif | <=1.11.0-1<=1.15.1-1 | 1.18.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29659 is a vulnerability in libheif 1.15.1 that causes a segmentation fault and denial of service when processing crafted heif images.
The severity of CVE-2023-29659 is medium with a CVSS score of 6.5.
Versions up to, but not including, 1.15.2 of libheif are affected by CVE-2023-29659.
To fix the CVE-2023-29659 vulnerability, you should update to version 1.15.2 or higher of libheif.
The CWE ID for CVE-2023-29659 is CWE-369.