In HeifDataSource::readAt of HeifDecoderImpl.cpp, there...
Moderate severity
Unreviewed
Published
Jan 28, 2025
to the GitHub Advisory Database
•
Updated Jan 28, 2025
Description
Published by the National Vulnerability Database
Jan 28, 2025
Published to the GitHub Advisory Database
Jan 28, 2025
Last updated
Jan 28, 2025
In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
References