CVE-2023-49460: High severity libheif vulnerability
Published Dec 7, 2023
·Updated
Last updated 24 July 2024
Other sources
libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decodeuncompressedimage.
Affected Software
2 affected componentsFixes available
debian/libheif<=1.11.0-1, <=1.15.1-1
1.18.1-2
struktur Libheif=1.17.5
Event History
Dec 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jun 26, 2024
Data Sourced
via Launchpad·09:46 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·10:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49460?
CVE-2023-49460 has been classified as a high-severity vulnerability due to the potential for segmentation violations.
2
How do I fix CVE-2023-49460?
To fix CVE-2023-49460, update libheif to version 1.18.1-2 or later.
3
What software is affected by CVE-2023-49460?
CVE-2023-49460 affects libheif version 1.17.5 and earlier versions on systems using Debian.
4
What impact does CVE-2023-49460 have on my system?
CVE-2023-49460 can lead to crashes and unexpected behavior in applications using the vulnerable libheif library.
5
Is there a known exploit for CVE-2023-49460?
As of now, there are no widely known exploits for CVE-2023-49460, but the vulnerability should still be addressed promptly.