CVE-2020-23109

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
03/11/2021
Last modified:
05/11/2021

Description

Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:struktur:libheif:1.6.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools