Headline
Debian Security Advisory 5796-1
Debian Linux Security Advisory 5796-1 - Multiple security issues were found in libheif, a library to parse HEIF and AVIF files, which could result in denial of service or potentially the execution of arbitrary code.
-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA512- -------------------------------------------------------------------------Debian Security Advisory DSA-5796-1 [email protected]://www.debian.org/security/ Moritz MuehlenhoffOctober 25, 2024 https://www.debian.org/security/faq- -------------------------------------------------------------------------Package : libheifCVE ID : CVE-2023-29659 CVE-2023-49462 CVE-2024-41311Multiple security issues were found in libheif, a library to parse HEIFand AVIF files, which could result in denial of service or potentiallythe execution of arbitrary code.For the stable distribution (bookworm), these problems have been fixed inversion 1.15.1-1+deb12u1.We recommend that you upgrade your libheif packages.For the detailed security status of libheif please refer toits security tracker page at:https://security-tracker.debian.org/tracker/libheifFurther information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: https://www.debian.org/security/Mailing list: [email protected] PGP SIGNATURE-----iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmcb3t8ACgkQEMKTtsN8Tjb/Zg//dGKfFs/w3AIgnaNKk+evGsFtaBdva6K2zkTOhGzVK+RoBCdP8egjfka+WCUYNQKVQr2XOd4ieih5DYg6CS/Tmn32X34sRN8St9UAz+sFXkkUZ9bBxSDS93LP1H+lGLfhqtHUAJv6febY+6RiAmV6vhzMIAuVTJxjdwGFvOFtu0f2aDQKEHTMIhpjpJDDCmjTciGmzjvSOpzVAw07nbeJFzvE/BR+wLg3fRMNG7RmQhZcG9O4B+RCHaJBzNAM1bM3q1OGkH5Ek3/owyIUtYft3iT2uGKZkZUzwJ4ZvOMxX9qyP22Gxl6+yfm5R1qDoXIBJMGVdjPIan3XK1XfKya9cCQkvNb+75W62WatkJw3TcomCFXXzcv2cKDOAbXGmIZHbAW+q6B5QWP86Ui10sBQsXW9lMmQW8mu4h13ZjgFelUsP6b9MWKKMRzFkqSh9me0bIlEvxl29/2HA08XnpV19//6j8PwANsBlGXnnDes0Y4uKrUKA8Q95zNuWG3owahc7z4+6nY92qoh5sswloIy1dXnhg6KYTuYL5JkxheIfOsh0fLG0eNfv5cV9mWKc9/A5BxSdBQz3x5bBNgH4R1L7z6/0+z/jo1Z6L904F4KsUiWnDeYKJNwhY+iOrDh5wDSrDA4+xVBtOo/q+6pR0c91GGoJImo9AEhXRKMGVKjjvw==JcU1-----END PGP SIGNATURE-----
Related news
Ubuntu Security Notice 7082-1 - Gerrard Tai discovered that libheif did not properly validate certain images, leading to out-of-bounds read and write vulnerability. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or to obtain sensitive information.
Ubuntu Security Notice 6847-1 - It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS.
Ubuntu Security Notice 6847-1 - It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS.
libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.