Opened 4 months ago

Closed 4 months ago

#23356 closed enhancement (fixed)

libheif-1.22.2

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

v1.22.1

Fixes

  • build issues with OpenJPEG plugin
  • non-plain C in header

Security

  • CVE TBD (​GHSA-r7qj-cg5r-r6vf) - Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder
  • (​GHSA-5hqq-636x-r3cr) - Out-of-bounds write in inline mask region API when source mask exceeds declared region

v1.22.2

Fixes missing heif_image_get_bayer_pattern_size() function.

Change History (3)

comment:1 by Joe Locash, 4 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 4 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

This update also fixes the build of ImageMagick with 1.22.0 and possibly other packages.

Fixed at 97bdaa5240. Leaving open for SA.

comment:3 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-103 issued

Note: See TracTickets for help on using tickets.