Advisories ยป MGASA-2024-0243

Updated libheif packages fix security vulnerabilities

Publication date: 28 Jun 2024
Modification date: 25 Mar 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-49460 , CVE-2023-49462 , CVE-2023-49463 , CVE-2023-49464

Description

Yuchuan Meng discovered that libheif incorrectly handled certain image
data.
An attacker could possibly use this issue to crash the program,
resulting  in a denial of service. (CVE-2023-49460, CVE-2023-49462,
CVE-2023-49463, CVE-2023-49464)
                

References

SRPMS

9/core

9/tainted