Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g8v9-c8m3-942v | Remote code execution in php-heic-to-jpg |
Thu, 19 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maestroerror
Maestroerror php-heic-to-jpg |
|
| CPEs | cpe:2.3:a:maestroerror:php-heic-to-jpg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Maestroerror
Maestroerror php-heic-to-jpg |
|
| Metrics |
ssvc
|
Thu, 19 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | php-heic-to-jpg <= 1.0.5 is vulnerable to remote code execution. An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below. | php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below. |
| References |
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Thu, 24 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | php-heic-to-jpg <= 1.0.5 is vulnerable to remote code execution. An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-19T15:14:41.209Z
Reserved: 2024-10-08T00:00:00.000Z
Link: CVE-2024-48514
Updated: 2024-10-25T19:25:01.446Z
Status : Deferred
Published: 2024-10-24T18:15:10.227
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-48514
No data.
OpenCVE Enrichment
No data.
Github GHSA