CVE-2025-29482

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:struktur:libheif:1.19.7:*:*:*:*:*:*:*

History

15 Apr 2025, 16:10

Type Values Removed Values Added
CPE cpe:2.3:a:struktur:libheif:1.19.7:*:*:*:*:*:*:*
First Time Struktur libheif
Struktur
References () https://github.com/lmarch2/poc/blob/main/libheif/libheif.md - () https://github.com/lmarch2/poc/blob/main/libheif/libheif.md - Exploit, Third Party Advisory

09 Apr 2025, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2
CWE CWE-120
References () https://github.com/lmarch2/poc/blob/main/libheif/libheif.md - () https://github.com/lmarch2/poc/blob/main/libheif/libheif.md -

08 Apr 2025, 18:13

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de desbordamiento de búfer en libheif 1.19.7 permite a un atacante local ejecutar código arbitrario a través del procesamiento SAO (Sample Adaptive Offset) de libde265.

07 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-07 20:15

Updated : 2025-04-15 16:10


NVD link : CVE-2025-29482

Mitre link : CVE-2025-29482

CVE.ORG link : CVE-2025-29482


JSON object : View

Products Affected

struktur

  • libheif
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')