Posted by Hanno Böck on Sep 19 Hi, Not sure if related, but this very recent commit https://github.com/strukturag/libheif/commit/6ce2bba558a27b63a508e81c085025f91c89899b sounds like it could be security-related and it is not part of the 1.23.4 release. Copying over commit description: --------- Reject in-band coded image sizes over the security limit for all codecs (GHSA-v8qw-hwjv-44hw) A crafted image can declare a small size in its container 'ispe' property while...

Read the full article at oss-security →