strukturag.libheif is vulnerable to Uncontrolled Resource Consumption
75
High Risk
libheif follows chains of derived-image references such as grid, overlay, and identity items without caching decode results or accounting for the allocations. A file with indirect reference chains forces a base image to be decoded hundreds of times and pre-allocates large tile-offset vectors outside the memory budget. Opening or decoding such a file leads to denial of service. The fix adds decode-result caching and enforces memory limits on the affected allocations.
You are affected if you decode untrusted HEIF files with a vulnerable version.
strukturag.libheif is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.23.1.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.