libheif-js is vulnerable to Out-of-bounds Read
75
High Risk
The embedded libheif build selects its YCbCr-to-RGB color-conversion routine using the reported bits-per-pixel. For uncompressed (unci) images with an odd component bit depth, the wide 16-bit conversion path is chosen for data stored one byte per pixel, miscomputing strides. Decoding such an image causes a heap out-of-bounds read that can crash the process or disclose adjacent heap memory. The fix selects the conversion routine using the storage bit depth.
You are affected if you are using a version that falls within the vulnerable range and your application decodes untrusted or externally influenced uncompressed (unci) HEIF images with an odd component bit depth.
libheif-js is vulnerable to Out-of-bounds Read in versions 1.17.1 - 1.18.0.
Upgrade the libheif-js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.