CVE-2023-49462: High severity libheif vulnerability
Published Dec 7, 2023
·Updated
Last updated 24 July 2024
Other sources
libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
Affected Software
2 affected componentsFixes available
debian/libheif<=1.11.0-1, <=1.15.1-1
1.18.1-2
struktur Libheif=1.17.5
Remediation
Patch Available
Event History
Dec 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jun 26, 2024
Data Sourced
via Launchpad·09:46 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·10:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49462?
CVE-2023-49462 has a medium severity due to a segmentation violation in libheif v1.17.5.
2
How do I fix CVE-2023-49462?
To fix CVE-2023-49462, upgrade libheif to version 1.18.1-2 or later.
3
Which versions of libheif are affected by CVE-2023-49462?
CVE-2023-49462 affects libheif version 1.17.5 and earlier versions up to 1.15.1-1.
4
What component is causing the problem in CVE-2023-49462?
The issue in CVE-2023-49462 is caused by the /libheif/exif.cc component.
5
Who is the vendor associated with CVE-2023-49462?
The vendor associated with CVE-2023-49462 is Struktur.