ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8755-1: libvips vulnerability

lowAdvisoryimportance 12
AI summary · glm-5.3

Ubuntu patches libvips flaw where crafted TIFF images converted to HEIF cause a crash, enabling denial of service.

USN-8755-1 fixes a libvips vulnerability in which specially crafted TIFF images are incorrectly handled when saved as HEIF, causing the library to crash. The impact is limited to denial of service with no code execution indicated. Ubuntu shipped updated packages.

  • Crafted TIFF images mishandled during HEIF conversion crash libvips
  • Impact limited to denial of service, no code execution indicated
Full article

It was discovered that libvips incorrectly handled specially crafted TIFF images when saving them as HEIF images. An attacker could possibly use this issue to cause libvips to crash, resulting in a denial of service.

This source does not provide full text. Read it at ubuntu.com.