CVE-2024-41311

In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
Configurations

Configuration 1 (hide)

cpe:2.3:a:struktur:libheif:1.17.6:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

24 Mar 2025, 14:41

Type Values Removed Values Added
First Time Struktur
Debian debian Linux
Debian
Struktur libheif
CPE cpe:2.3:a:struktur:libheif:1.17.6:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
References () https://gist.github.com/flyyee/79f1b224069842ee320115cafa5c35c0 - () https://gist.github.com/flyyee/79f1b224069842ee320115cafa5c35c0 - Third Party Advisory
References () https://github.com/strukturag/libheif/commit/a3ed1b1eb178c5d651d6ac619c8da3d71ac2be36 - () https://github.com/strukturag/libheif/commit/a3ed1b1eb178c5d651d6ac619c8da3d71ac2be36 - Patch
References () https://github.com/strukturag/libheif/issues/1226 - () https://github.com/strukturag/libheif/issues/1226 - Exploit, Issue Tracking
References () https://github.com/strukturag/libheif/pull/1227 - () https://github.com/strukturag/libheif/pull/1227 - Issue Tracking, Patch
References () https://lists.debian.org/debian-lts-announce/2024/10/msg00025.html - () https://lists.debian.org/debian-lts-announce/2024/10/msg00025.html - Mailing List

Information

Published : 2024-10-15 21:15

Updated : 2025-03-24 14:41


NVD link : CVE-2024-41311

Mitre link : CVE-2024-41311

CVE.ORG link : CVE-2024-41311


JSON object : View

Products Affected

debian

  • debian_linux

struktur

  • libheif
CWE
CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write