CVE-2023-0996
Summary
| CVE | CVE-2023-0996 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-24 04:15:00 UTC |
| Updated | 2023-11-07 04:02:00 UTC |
| Description | There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. |
Risk And Classification
Problem Types: CWE-120
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2023-0996 | GovTech CSG Security Advisories | MISC | govtech-csg.github.io | |
| JS: Fix copying of strided image data. by fancycode · Pull Request #759 · strukturag/libheif · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183611 Debian Security Update for libheif (CVE-2023-0996)