Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Skensita

#31951of 53,632
7.8Total CVSS
Vulnerabilities · 1
PT-2023-3276
7.8
2023-04-03
Libheif · Libheif · CVE-2023-29659
**Name of the Vulnerable Software and Affected Versions** libheif version 1.15.1 **Description** A Segmentation fault caused by a floating point exception exists in libheif using crafted heif images via the `heif::Fraction::round()` function in box.cc, which causes a denial of service. The vulnerability is related to a floating point exception in the `heif::Fraction::round()` function. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service. **Recommendations** For libheif version 1.15.1, consider disabling the `heif::Fraction::round()` function in box.cc as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.