Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0996

Опубликовано: 24 фев. 2023
Источник: debian
EPSS Низкий

Описание

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libheiffixed1.15.1-1package
libheifno-dsabusterpackage

Примечания

  • https://github.com/strukturag/libheif/pull/759

  • https://govtech-csg.github.io/security-advisories/2023/02/24/CVE-2023-0996.html

EPSS

Процентиль: 38%
0.00161
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

CVSS3: 7.8
nvd
больше 2 лет назад

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

suse-cvrf
около 2 лет назад

Security update for libheif

CVSS3: 7.8
redos
около 2 лет назад

Уязвимость libheif

CVSS3: 7.8
github
больше 2 лет назад

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

EPSS

Процентиль: 38%
0.00161
Низкий