Out-of-bounds write in libheif - CVE-2024-41311
Published: October 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the ImageOverlay::parse() in context.cc. A remote attacker can create a specially crafted image file, trick the victim into opening it using the affected software, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
Desktop Applications Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Fedora
gdk-pixbuf-loader-libheif
libheif-devel
libheif-debugsource
gdk-pixbuf-loader-libheif-debuginfo
libheif1
libheif1-debuginfo
libheif1-32bit
libheif1-32bit-debuginfo
libheif1-64bit
libheif1-64bit-debuginfo
libheif (Debian package)
libheif1 (Ubuntu package)
libheif
How to mitigate CVE-2024-41311
gdk-pixbuf-loader-libheif - update to 1.12.0-150400.3.14.1
libheif-devel - update to 1.12.0-150400.3.14.1
libheif-debugsource - update to 1.12.0-150400.3.14.1
gdk-pixbuf-loader-libheif-debuginfo - update to 1.12.0-150400.3.14.1
libheif1 - update to 1.12.0-150400.3.14.1
libheif1-debuginfo - update to 1.12.0-150400.3.14.1
libheif1-32bit - update to 1.12.0-150400.3.14.1
libheif1-32bit-debuginfo - update to 1.12.0-150400.3.14.1
libheif1-64bit - update to 1.12.0-150400.3.14.1
libheif1-64bit-debuginfo - update to 1.12.0-150400.3.14.1
libheif (Debian package) - update to 1.15.1-1+deb12u1
libheif1 (Ubuntu package) - update to 1.17.6-1ubuntu4.1
libheif - addressed in versions 1.19.5-3.fc40, 1.19.5-3.fc41