Mageia 2023-0144: libheif security update
Summary
Vulnerability in the strided image data parsing code in the emscripten
wrapper for libheif. An attacker could exploit this through a crafted
image file to cause a buffer overflow in linear memory during a memcpy
call. (CVE-2023-0996)
References
- https://bugs.mageia.org/show_bug.cgi?id=31768
- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014381.html
- https://bugzilla.suse.com/show_bug.cgi?id=1208640
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0996
Resolution
MGASA-2023-0144 - Updated libheif packages fix security vulnerability
SRPMS
- 8/core/libheif-1.10.0-1.2.mga8
- 8/tainted/libheif-1.10.0-1.2.mga8.tainted