Bugzilla – Bug 1208640
VUL-0: CVE-2023-0996: libheif: buffer overflow in heif_js_decode_image in libheif
Last modified: 2024-06-21 18:44:47 UTC
CVE-2023-0996 There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0996 https://www.cve.org/CVERecord?id=CVE-2023-0996 https://github.com/strukturag/libheif/pull/759 https://govtech-csg.github.io/security-advisories/2023/02/24/CVE-2023-0996.html
Affected: - SUSE:SLE-15-SP4:Update - openSUSE:Factory
Submitted for 15sp4/libheif. Reassigning to openSUSE maintainer for Factory submit. Note that rq#1066258 fixes the issue.
This was fixed in SR#1066258 which was accepted over a year ago