CVE-2024-41311
published 2024-10-15CVE-2024-41311: In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an…
PriorityP340high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.83%
53.3th percentile
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libheif | < libheif 1.15.1-1+deb12u1 (bookworm) | libheif 1.15.1-1+deb12u1 (bookworm) |
| struktur | libheif | — | — |
| struktur | libheif | >= 0 < 1.11.0-1+deb11u1 | 1.11.0-1+deb11u1 |
| struktur | libheif | >= 0 < 1.15.1-1+deb12u1 | 1.15.1-1+deb12u1 |
| struktur | libheif | >= 0 < 1.18.1-1 | 1.18.1-1 |
| struktur | libheif | >= 0 < 1.18.1-1 | 1.18.1-1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerability
vendor_ubuntu·2024-10-23
CVE-2024-41311 libheif vulnerability
Title: libheif vulnerability
Summary: libheif could be made to crash or read sensitive data if it opened a
specially crafted file
Gerrard Tai discovered that libheif did not properly validate certain
images, leading to out-of-bounds read and write vulnerability. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service or to
obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2024-41311: libheif - In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif ...
vendor_debian·2024·CVSS 8.1
CVE-2024-41311 [HIGH] CVE-2024-41311: libheif - In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif ...
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
Scope: local
bookworm: resolved (fixed in 1.15.1-1+deb12u1)
bullseye: resolved (fixed in 1.11.0-1+deb11u1)
forky: resolved (fixed in 1.18.1-1)
sid: resolved (fixed in 1.18.1-1)
trixie: resolved (fixed in 1.18.1-1)
OSV
CVE-2024-41311: In Libheif 1
osv·2024-10-15·CVSS 8.1
CVE-2024-41311 [HIGH] CVE-2024-41311: In Libheif 1
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
GHSA
GHSA-mwf7-wfvq-vc32: In Libheif 1
ghsa_unreviewed·2024-10-15
CVE-2024-41311 [HIGH] CWE-125 GHSA-mwf7-wfvq-vc32: In Libheif 1
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gist.github.com/flyyee/79f1b224069842ee320115cafa5c35c0https://github.com/strukturag/libheif/commit/a3ed1b1eb178c5d651d6ac619c8da3d71ac2be36https://github.com/strukturag/libheif/issues/1226https://github.com/strukturag/libheif/pull/1227https://lists.debian.org/debian-lts-announce/2024/10/msg00025.html
2024-10-15
Published