CVE-2024-25269: High severity libheif vulnerability
Published Mar 5, 2024
·Updated
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
Affected Software
2 affected components
struktur Libheif<=1.17.6
libheif libheif<=1.17.6
Event History
Mar 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25269?
The severity of CVE-2024-25269 is classified as moderate due to its potential to cause denial of service.
2
How do I fix CVE-2024-25269?
To fix CVE-2024-25269, update libheif to version 1.17.7 or higher.
3
What kind of attack can CVE-2024-25269 facilitate?
CVE-2024-25269 can facilitate a denial of service attack due to a memory leak.
4
Is CVE-2024-25269 exploitable remotely?
Yes, CVE-2024-25269 can be exploited remotely if the vulnerable libheif software is used in a susceptible application.
5
Which versions of libheif are affected by CVE-2024-25269?
All versions of libheif up to and including 1.17.6 are affected by CVE-2024-25269.