Headline
Ubuntu Security Notice USN-7082-1
Ubuntu Security Notice 7082-1 - Gerrard Tai discovered that libheif did not properly validate certain images, leading to out-of-bounds read and write vulnerability. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or to obtain sensitive information.
==========================================================================Ubuntu Security Notice USN-7082-1October 23, 2024libheif vulnerability==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 24.04 LTSSummary:libheif could be made to crash or read sensitive data if it opened aspecially crafted fileSoftware Description:- libheif: an ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoderDetails:Gerrard Tai discovered that libheif did not properly validate certainimages, leading to out-of-bounds read and write vulnerability. If a useror automated system were tricked into opening a specially crafted file, anattacker could possibly use this issue to cause a denial of service or toobtain sensitive information.Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 24.04 LTS libheif1 1.17.6-1ubuntu4.1In general, a standard system update will make all the necessary changes.References: https://ubuntu.com/security/notices/USN-7082-1 CVE-2024-41311Package Information: https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.1
Related news
Debian Security Advisory 5796-1
Debian Linux Security Advisory 5796-1 - Multiple security issues were found in libheif, a library to parse HEIF and AVIF files, which could result in denial of service or potentially the execution of arbitrary code.