Source: libheif Version: 1.23.3-1 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Dear maintainer, The following vulnerability was published for libheif. CVEs arel not allocated yet. GHSA-vg7w-rp49-4fc2[1] — High, 8.7 — max_items not enforced for iinf child boxes. GHSA-xrp2-63fq-jm8q[2] — High, 8.7 — unbounded iref list and unbounded recursion. GHSA-prgh-72vc-3xmc[3] — High, 8.7 — lock-order inversion deadlocks parallel grid tile decoding. GHSA-4rv4-953r-p24q[4] — Moderate, 6.9 — leak and uncaught exception in the raw sequence sample API. GHSA-fqpw-fj22-78w4[5] — Moderate, 6.3 — heap over-read in encoder plugins on mismatched bit depths. GHSA-rhgw-q5g8-xjh2[6] — Moderate, 4.3 — heap over-read in the WebCodecs decoder. For further information see: [1] https://github.com/strukturag/libheif/security/advisories/GHSA-vg7w-rp49-4fc2 [2] https://github.com/strukturag/libheif/security/advisories/GHSA-xrp2-63fq-jm8q [3] https://github.com/strukturag/libheif/security/advisories/GHSA-prgh-72vc-3xmc [4] https://github.com/strukturag/libheif/security/advisories/GHSA-4rv4-953r-p24q [5] https://github.com/strukturag/libheif/security/advisories/GHSA-fqpw-fj22-78w4 [6] https://github.com/strukturag/libheif/security/advisories/GHSA-rhgw-q5g8-xjh2 Regards, Aron

