漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft HEIF Image Extensions 安全漏洞
Vulnerability Description
Microsoft HEIF Image Extensions是美国Microsoft公司的一款HEIF图像扩展组件。 Microsoft HEIF Image Extensions 1.2.22.0版本存在安全漏洞,该漏洞可导致越界读取。
CVSS Information
N/A
Vulnerability Type
N/A