PT-2022-7255 · Libde265+4 · Libde265+4
Peng Deng
·
Published
2022-10-10
·
Updated
2025-06-25
·
CVE-2022-43242
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Libde265 versions 1.0.8
Description
The issue is related to a heap-buffer-overflow vulnerability via the
mc luma function in motion.cc, which allows attackers to cause a Denial of Service (DoS) via a crafted video file. This vulnerability is associated with the processing of unsigned char data type and can be exploited by a remote attacker.Recommendations
For Libde265 version 1.0.8, update to version 1.0.11 to fix the security issue. As a temporary workaround, consider restricting the use of the
mc luma function in motion.cc to minimize the risk of exploitation. Avoid using the mc luma function with crafted video files until the issue is resolved.Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Libde265
Linuxmint
Red Os
Ubuntu