PT-2022-7271 · Libde265+3 · Libde265+3
Fdu-Secopened
·
Published
2022-02-11
·
Updated
2025-01-28
·
CVE-2022-43250
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Libde265 version 1.0.8
Description
The issue is related to a heap-buffer-overflow vulnerability in the
put qpel 0 0 fallback 16 function, located in fallback-motion.cc, which is part of the Libde265 video codec implementation. This vulnerability can be exploited by an attacker to cause a Denial of Service (DoS) using a specially crafted video file.Recommendations
For Libde265 version 1.0.8, update to version 1.0.11 to fix the security issue.
As a temporary workaround, consider restricting the use of the
put qpel 0 0 fallback 16 function in fallback-motion.cc until a patch is available.Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Libde265
Linuxmint
Ubuntu