ECHO-0bd8-3c77-95c2

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-0bd8-3c77-95c2.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-0bd8-3c77-95c2
Upstream
Withdrawn
2026-06-02T10:56:03Z
Published
2026-05-26T09:52:21Z
Modified
2026-09-15T03:33:45Z
Summary
Vulnerability is in libheif's image-sequence / ISOBMFF track parsing, which was added in v1.20.0. v1.19.8 — the version we ship — has no track parsing at all (no Box_stsc / Box_stts / Box_saiz / TrackBox / MovieBox), so the vulnerable code is not present.
Details
References

Affected packages

Echo / libheif

Package

Name
libheif
Purl
pkg:deb/echo/libheif

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.8-1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-0bd8-3c77-95c2.json"