In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Mar 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Debian
Debian debian Linux |
|
CPEs | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | |
Vendors & Products |
Debian
Debian debian Linux |
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 16 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Struktur
Struktur libheif |
|
Weaknesses | CWE-125 CWE-787 |
|
CPEs | cpe:2.3:a:struktur:libheif:1.17.6:*:*:*:*:*:*:* | |
Vendors & Products |
Struktur
Struktur libheif |
|
Metrics |
cvssV3_1
|
Tue, 15 Oct 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-23T00:10:12.649Z
Reserved: 2024-07-18T00:00:00
Link: CVE-2024-41311

Updated: 2024-10-23T00:10:12.649Z

Status : Analyzed
Published: 2024-10-15T21:15:10.923
Modified: 2025-03-24T14:41:38.683
Link: CVE-2024-41311

No data.