PT-2023-8875 · Libde265+4 · Libde265+4
Litios
·
Published
2023-11-22
·
Updated
2024-04-02
·
CVE-2023-43887
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Libde265 version 1.0.12
Description
The issue is related to a buffer overflow in the
pic parameter set::dump() function of the h.265 Libde265 video codec, specifically through the num tile columns and num tile row parameters. This could allow a remote attacker to disclose protected information or cause a denial of service.Recommendations
For Libde265 version 1.0.12, consider disabling the
pic parameter set::dump() function until a patch is available to prevent exploitation of the buffer overflow vulnerability via the num tile columns and num tile row parameters.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Libde265
Linuxmint
Red Os
Ubuntu