strukturag.libheif is vulnerable to Uncontrolled Resource Consumption
75
High Risk
libheif decompresses brotli- and zlib-compressed metadata items while opening a file without enforcing any output-size limit. A HEIF file carrying a highly compressed mime item expands to an enormous buffer, and the allocations bypass the configured memory budget. Opening such a file drives unbounded memory allocation and an out-of-memory crash before any decode step runs. The fix caps decompressed output size and routes the allocations through the memory-limit handler.
You are affected if you open or parse untrusted or externally influenced HEIF files with a vulnerable version.
strukturag.libheif is vulnerable to Uncontrolled Resource Consumption in versions 1.19.0 - 1.23.1.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.