Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99291
HistorySep 23, 2021 - 12:00 a.m.

HEIF Global Buffer Overflow Vulnerability (CNVD-2021-99291)

2021-09-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
heif
global buffer overflow
vulnerability
hevcdecoderconfigurationrecord
getpicwidth
execution code
image format
security issue

EPSS

0.001

Percentile

39.8%

HEIF refers to High Efficiency Image File Format, a file format for single images or image sequences. hevcDecoderConfigurationRecord::getPicWidth() function in hevcdecoderconfigrecord.cpp in HEIF 3.6.2 and earlier versions has global buffer overflow vulnerability. An attacker can exploit this vulnerability to execute code.

EPSS

0.001

Percentile

39.8%

Related for CNVD-2021-99291