Advisories ยป MGASA-2024-0243

Updated libheif packages fix security vulnerabilities

Publication date: 28 Jun 2024
Modification date: 28 Jun 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-49460 , CVE-2023-49462 , CVE-2023-49463 , CVE-2023-49464

Description

It was discovered that libheif incorrectly handled certain image data.
An attacker could possibly use this issue to crash the program,
resulting  in a denial of service. (CVE-2019-11471)
Reza Mirzazade Farkhani discovered that libheif incorrectly handled
certain image data. An attacker could possibly use this issue to crash
the program, resulting in a denial of service. (CVE-2020-23109)
Eugene Lim discovered that libheif incorrectly handled certain image
data.
An attacker could possibly use this issue to crash the program,
resulting  in a denial of service. (CVE-2023-0996)
Min Jang discovered that libheif incorrectly handled certain image data.
An attacker could possibly use this issue to crash the program,
resulting  in a denial of service. (CVE-2023-29659)
Yuchuan Meng discovered that libheif incorrectly handled certain image
data.
An attacker could possibly use this issue to crash the program,
resulting  in a denial of service. (CVE-2023-49460, CVE-2023-49462,
CVE-2023-49463, CVE-2023-49464)
                

References

SRPMS

9/core

9/tainted