Libheif · Libheif · CVE-2023-29659
**Name of the Vulnerable Software and Affected Versions**
libheif version 1.15.1
**Description**
A Segmentation fault caused by a floating point exception exists in libheif using crafted heif images via the `heif::Fraction::round()` function in box.cc, which causes a denial of service. The vulnerability is related to a floating point exception in the `heif::Fraction::round()` function. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service.
**Recommendations**
For libheif version 1.15.1, consider disabling the `heif::Fraction::round()` function in box.cc as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.