CVE-2020-23109: Struktur Libheif

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.

Affected products

Published 2021-11-03. Last modified 2026-06-17.