CVE-2023-49463: High severity libheif vulnerability
Published Dec 7, 2023
·Updated
Last updated 24 July 2024
Other sources
libheif v1.17.5 was discovered to contain a segmentation violation via the function findexiftag at /libheif/exif.cc.
Affected Software
2 affected componentsFixes available
debian/libheif<=1.11.0-1, <=1.15.1-1
1.18.1-2
struktur Libheif=1.17.5
Remediation
Patch Available
Event History
Dec 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jun 26, 2024
Data Sourced
via Launchpad·09:46 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·10:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49463?
The severity of CVE-2023-49463 is rated as high with a CVSS score of 8.8.
2
How can I mitigate CVE-2023-49463?
To mitigate CVE-2023-49463, users should update to a patched version of libheif that addresses the segmentation violation in the function find_exif_tag.