In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade strukturag/libheif to version 1.23.2 or higher.
Affected versions of this package are vulnerable to Out-of-bounds Write through ImageItem::decode_image() in libheif/image-items/image_item.cc. An attacker can trigger memory corruption by supplying a malformed HEIC image with mismatched alpha-plane geometry that is decoded and scaled against the wrong dimensions. This can crash the decoder or be leveraged for remote code execution when an application processes the crafted image.