CVE-2023-49464: High severity libheif vulnerability
Published Dec 7, 2023
·Updated
Last updated 24 July 2024
Other sources
libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::getlumabitsperpixelfromconfigurationunci.
Affected Software
2 affected componentsFixes available
debian/libheif<=1.11.0-1, <=1.15.1-1
1.18.1-2
struktur Libheif=1.17.5
Remediation
Patch Available
Event History
Dec 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jun 26, 2024
Data Sourced
via Launchpad·09:46 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·10:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49464?
CVE-2023-49464 has a high severity due to its potential to cause segmentation violations.
2
How do I fix CVE-2023-49464?
To fix CVE-2023-49464, upgrade to libheif version 1.18.1-2 or later.
3
Which versions of libheif are vulnerable to CVE-2023-49464?
Libheif version 1.17.5 and any versions prior to 1.18.1 are vulnerable to CVE-2023-49464.
4
What functions are affected by CVE-2023-49464?
CVE-2023-49464 affects the UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci function.
5
Is CVE-2023-49464 present in Debian packages?
Yes, CVE-2023-49464 is present in Debian packages of libheif versions up to 1.15.1-1.