ZeroHour
Vendor

strukturag

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Re: Vulnerabilities in libheif and libde265

Hanno Böck flags a security-relevant libheif fix (GHSA-v8qw-hwjv-44hw) rejecting oversized in-band coded image sizes, absent from release 1.23.4.

A follow-up to the libheif/libde265 vulnerability discussion notes that commit 6ce2bba in strukturag/libheif rejects in-band coded image sizes exceeding the security limit for all codecs, tracked as GHSA-v8qw-hwjv-44hw. A crafted image can declare a small size in its container 'ispe' property while the actual coded image is larger, bypassing prior validation. The fix was not included in the libheif 1.23.4 release.

oss-security · 8h agoVulnerability 2 sources

Vulnerabilities in libheif and libde265

Multiple new security advisories affect the libheif and libde265 codecs; users should verify versions against the published fixes.

An oss-security post highlights numerous recent security advisories for libheif and libde265, the open-source libraries used to decode HEIF/HEVC images. The GitHub security pages of both strukturag projects list several new advisories published over the past few months. The poster, Alan Coopersmith, urges anyone using these codecs to check their versions, while noting the related heif-heist.com site is more promotional than informational.

oss-securityupdated · 8h agofirst · 1d agoVulnerability 2 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.