MGASA-2023-0144 - Updated libheif packages fix security vulnerability

Publication date: 15 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0144.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2023-0996

Vulnerability in the strided image data parsing code in the emscripten
wrapper for libheif. An attacker could exploit this through a crafted
image file to cause a buffer overflow in linear memory during a memcpy
call. (CVE-2023-0996)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31768
- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014381.html
- https://bugzilla.suse.com/show_bug.cgi?id=1208640
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0996

SRPMS:
- 8/core/libheif-1.10.0-1.2.mga8
- 8/tainted/libheif-1.10.0-1.2.mga8.tainted

Mageia 2023-0144: libheif security update

Vulnerability in the strided image data parsing code in the emscripten wrapper for libheif

Summary

Vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. (CVE-2023-0996)

References

- https://bugs.mageia.org/show_bug.cgi?id=31768

- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014381.html

- https://bugzilla.suse.com/show_bug.cgi?id=1208640

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0996

Resolution

MGASA-2023-0144 - Updated libheif packages fix security vulnerability

SRPMS

- 8/core/libheif-1.10.0-1.2.mga8

- 8/tainted/libheif-1.10.0-1.2.mga8.tainted

Severity
Publication date: 15 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0144.html
Type: security
CVE: CVE-2023-0996

Related News