Source: libheif
Version: 1.23.3-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Dear maintainer,

The following vulnerability was published for libheif. CVEs arel not
allocated yet.

GHSA-vg7w-rp49-4fc2[1] — High, 8.7 — max_items not enforced for iinf
child boxes.
GHSA-xrp2-63fq-jm8q[2] — High, 8.7 — unbounded iref list and unbounded
recursion.
GHSA-prgh-72vc-3xmc[3] — High, 8.7 — lock-order inversion deadlocks
parallel grid tile decoding.
GHSA-4rv4-953r-p24q[4] — Moderate, 6.9 — leak and uncaught exception
in the raw sequence sample API.
GHSA-fqpw-fj22-78w4[5] — Moderate, 6.3 — heap over-read in encoder
plugins on mismatched bit depths.
GHSA-rhgw-q5g8-xjh2[6] — Moderate, 4.3 — heap over-read in the
WebCodecs decoder.

For further information see:

[1] 
https://github.com/strukturag/libheif/security/advisories/GHSA-vg7w-rp49-4fc2
[2] 
https://github.com/strukturag/libheif/security/advisories/GHSA-xrp2-63fq-jm8q
[3] 
https://github.com/strukturag/libheif/security/advisories/GHSA-prgh-72vc-3xmc
[4] 
https://github.com/strukturag/libheif/security/advisories/GHSA-4rv4-953r-p24q
[5] 
https://github.com/strukturag/libheif/security/advisories/GHSA-fqpw-fj22-78w4
[6] 
https://github.com/strukturag/libheif/security/advisories/GHSA-rhgw-q5g8-xjh2

Regards,
Aron

Reply via email to