Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0996

Опубликовано: 24 фев. 2023
Источник: debian
EPSS Низкий

Описание

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libheiffixed1.15.1-1package
libheifno-dsabusterpackage

Примечания

  • https://github.com/strukturag/libheif/pull/759

  • https://govtech-csg.github.io/security-advisories/2023/02/24/CVE-2023-0996.html

EPSS

Процентиль: 40%
0.00184
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

CVSS3: 7.8
nvd
почти 3 года назад

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

suse-cvrf
больше 2 лет назад

Security update for libheif

CVSS3: 7.8
redos
больше 2 лет назад

Уязвимость libheif

CVSS3: 7.8
github
почти 3 года назад

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

EPSS

Процентиль: 40%
0.00184
Низкий