CyberRota Analysis
AI-GeneratedVersions 1.19.0 through 1.21.2 of libheif are vulnerable to a heap out-of-bounds write due to improper handling of crafted HEIF files, which can lead to arbitrary code execution through manipulation of the C++ vtable pointer. This vulnerability poses a medium risk, particularly for applications that utilize libheif for decoding HEIF and AVIF files. Developers and security teams using affected versions should prioritize upgrading to version 1.22.0 to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)