Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Mageia 9: MGASA-2024-0352 critical: libheif buffer overflow issue

mageia
Calendar Grey November 9, 2024
Scroller Mageia
Patch updates addressing the vulnerability in libheif for Mageia users have been released, which could permit unauthorized out-of-bounds access. Click here for further information.
In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write

Summary

In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311)

References

- https://bugs.mageia.org/show_bug.cgi?id=33662

- https://ubuntu.com/security/notices/USN-7082-1

- https://www.cve.org/CVERecord?id=CVE-2024-41311

Resolution

SRPMS

- 9/core/libheif-1.16.2-1.2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 09 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0352.html
Type: security
CVE: CVE-2024-41311

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.