PT-2022-7262 · Libde265+3 · Libde265+3
Peng Deng
·
Published
2022-10-10
·
Updated
2025-01-28
·
CVE-2022-43238
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Libde265 version 1.0.8
Description
The issue is related to the
ff hevc put hevc qpel h 3 v 3 sse() function in the Libde265 video codec implementation, which can cause a buffer overflow in memory. This can be exploited by a remote attacker using a specially crafted video file to cause a Denial of Service (DoS). The vulnerability allows attackers to cause a crash via the ff hevc put hevc qpel h 3 v 3 sse() function in sse-motion.cc.Recommendations
For Libde265 version 1.0.8, update to version 1.0.11 to fix the security issue. As a temporary workaround, consider disabling the
ff hevc put hevc qpel h 3 v 3 sse() function until a patch is available. Restrict access to the sse-motion.cc module to minimize the risk of exploitation. Avoid using crafted video files that can trigger the Denial of Service (DoS) until the issue is resolved.Exploit
Fix
DoS
Out of bounds Read
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Libde265
Linuxmint
Ubuntu