strukturag.libheif is vulnerable to Out-of-bounds Read
40
Medium Risk
libheif's inline-mask region writer API accepts a caller-supplied mask-data length without checking it against the region width and height. The reader later derives the read length from the region geometry alone and walks the mask buffer accordingly. When the supplied buffer is smaller than the geometry requires, the reader performs a heap out-of-bounds read that can crash the process and fold adjacent heap bytes into the returned mask image. The fix validates the mask-data length against the required buffer size.
You are affected if you are using a version that falls within the vulnerable range and you build region items with the inline-mask writer API using an untrusted or incorrectly sized mask-data buffer.
strukturag.libheif is vulnerable to Out-of-bounds Read in versions 0.0.1 - 1.23.1.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.