脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe
脆弱性説明
libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe && uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue.
CVSS情報
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
脆弱性タイプ
空指针解引用
脆弱性タイトル
strukturag libheif 异常处理不当漏洞
脆弱性説明
strukturag libheif是strukturag的图像编解码库。 strukturag libheif 1.22.0之前版本存在异常处理不当漏洞,该漏洞源于在公共C API `heif_image_handle_get_image_tiling()`中处理格式异常的未压缩HEIF图像项目时,因项目有关联的`uncC`属性但无关联的`ispe`属性,导致触发断言或空指针读取,可能导致拒绝服务。
CVSS情報
N/A
脆弱性タイプ
N/A