PT-2023-8338 · Libde265+5 · Libde265+5

Fdu-Sec

·

Published

2023-11-23

·

Updated

2024-04-08

·

CVE-2023-49465

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Libde265 version 1.0.14
Description The issue is related to a heap-buffer-overflow vulnerability in the derive spatial luma vector prediction function. This vulnerability may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is associated with the Libde265 video codec implementation of the h.265 standard.
Recommendations For Libde265 version 1.0.14, consider disabling the derive spatial luma vector prediction function as a temporary workaround until a patch is available. Restrict access to the motion.cc file to minimize the risk of exploitation. Avoid using the vulnerable function in the affected video codec implementation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8314
BDU:2024-00520
BDU:2024-01357
CVE-2023-49465
DLA-3699-1
USN-6677-1

Affected Products

Alt Linux
Astra Linux
Libde265
Linuxmint
Red Os
Ubuntu