Vulnerabilities in libheif and libde265
Multiple new security advisories affect the libheif and libde265 codecs; users should verify versions against the published fixes.
An oss-security post highlights numerous recent security advisories for libheif and libde265, the open-source libraries used to decode HEIF/HEVC images. The GitHub security pages of both strukturag projects list several new advisories published over the past few months. The poster, Alan Coopersmith, urges anyone using these codecs to check their versions, while noting the related heif-heist.com site is more promotional than informational.
- Several new security advisories published recently for libheif and libde265
- Both codec libraries are widely used for HEIF/HEVC image decoding
- Users urged to check installed versions against vendor advisories
- heif-heist.com campaign site described as promotional rather than informational
Posted by Alan Coopersmith on Sep 18 https://heif-heist.com/ seems more promotional than informational at this https://github.com/strukturag/libheif/security and https://github.com/strukturag/libde265/security both list quite a few new advisories for each in the past few months, so anyone using these codecs should check their versions....
This source does not provide full text. Read it at seclists.org.