Source: libheif Version: 1.15.1-1 Severity: important Tags: security upstream Forwarded: https://github.com/strukturag/libheif/issues/794 X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Hi, The following vulnerability was published for libheif. CVE-2023-29659[0]: | A Segmentation fault caused by a floating point exception exists in | libheif 1.15.1 using crafted heif images via the | heif::Fraction::round() function in box.cc, which causes a denial of | service. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-29659 https://www.cve.org/CVERecord?id=CVE-2023-29659 [1] https://github.com/strukturag/libheif/issues/794 [2] https://github.com/strukturag/libheif/commit/e05e15b57a38ec411cb9acb38512a1c36ff62991 Please adjust the affected versions in the BTS as needed. Regards, Salvatore