Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
libheif has Heap Out Of Bounds Write in unci subsystem
Vulnerability Description
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Vulnerability Type
跨界内存写
Vulnerability Title
strukturag libheif 缓冲区错误漏洞
Vulnerability Description
strukturag libheif是strukturag的图像编解码库。 strukturag libheif 1.19.0版本至1.21.2版本存在缓冲区错误漏洞,该漏洞源于特制HEIF文件触发了非压缩图块解码器中的堆越界写入,覆盖了相邻对象的C++虚表指针,可能导致攻击者控制下一条虚函数调用地址。
CVSS Information
N/A
Vulnerability Type
N/A