ECHO-c4ce-3570-7d06

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-c4ce-3570-7d06.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-c4ce-3570-7d06
Upstream
Withdrawn
2026-07-15T22:42:27Z
Published
2026-07-02T20:24:58Z
Modified
2026-09-15T03:33:46Z
Summary
Vulnerability is in libheif's HEIF sequence parser (Box_stsz::parse in libheif/sequences/seq_boxes.cc, plus track.cc / chunk.cc). This sequence / ISOBMFF track parsing was added in v1.20.0; v1.19.8 — the version we ship — has no sequences/ directory and no Box_stsz at all (verified: no such file or symbol in the v1.19.8 source), so the vulnerable code is not present. The GHSA lists "affected >= 1.19.0", but that range is imprecise: the introducing commit 58c21087 is not in the v1.19.8 tag.
Details
References

Affected packages

Echo / libheif

Package

Name
libheif
Purl
pkg:deb/echo/libheif

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.8-1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-c4ce-3570-7d06.json"