First published: Tue Jun 25 2024(Updated: )
It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-11471) Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-23109) Eugene Lim discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-0996) Min Jang discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-29659) Yuchuan Meng discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 23.10. (CVE-2023-49460, CVE-2023-49462, CVE-2023-49463, CVE-2023-49464)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/heif-gdk-pixbuf | <1.16.2-2ubuntu1.1 | 1.16.2-2ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libheif-dev | <1.16.2-2ubuntu1.1 | 1.16.2-2ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libheif-plugin-libde265 | <1.16.2-2ubuntu1.1 | 1.16.2-2ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libheif1 | <1.16.2-2ubuntu1.1 | 1.16.2-2ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/heif-gdk-pixbuf | <1.12.0-2ubuntu0.1~esm1 | 1.12.0-2ubuntu0.1~esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libheif-dev | <1.12.0-2ubuntu0.1~esm1 | 1.12.0-2ubuntu0.1~esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libheif1 | <1.12.0-2ubuntu0.1~esm1 | 1.12.0-2ubuntu0.1~esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/heif-gdk-pixbuf | <1.6.1-1ubuntu0.1~esm1 | 1.6.1-1ubuntu0.1~esm1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libheif-dev | <1.6.1-1ubuntu0.1~esm1 | 1.6.1-1ubuntu0.1~esm1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libheif1 | <1.6.1-1ubuntu0.1~esm1 | 1.6.1-1ubuntu0.1~esm1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libheif-dev | <1.1.0-2ubuntu0.1~esm1 | 1.1.0-2ubuntu0.1~esm1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/libheif1 | <1.1.0-2ubuntu0.1~esm1 | 1.1.0-2ubuntu0.1~esm1 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-6847-1 is considered a denial of service vulnerability due to improper handling of image data by libheif.
To fix USN-6847-1, update the affected packages to their recommended versions like 1.16.2-2ubuntu1.1 or later for Ubuntu 23.10.
USN-6847-1 affects users of Ubuntu 18.04 LTS and several subsequent versions using the libheif library.
An attacker could exploit USN-6847-1 to crash applications that utilize libheif, leading to a denial of service condition.
Check if your system is running an affected version of libheif, such as versions below 1.16.2-2ubuntu1.1 on Ubuntu.