CVE-2020-21596: Buffer Overflow
Published Sep 16, 2021
·Updated
Last updated 24 July 2024
Other sources
libde265 v1.0.4 contains a global buffer overflow in the decodeCABACbit function, which can be exploited via a crafted a file.
Affected Software
4 affected componentsFixes available
debian/libde265
1.0.11-0+deb11u31.0.11-0+deb11u11.0.11-1+deb12u21.0.15-1
struktur libde265=1.0.4
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Sep 16, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jul 15, 2022
Data Sourced
10:36 PM
SeverityAffected Software
Jan 30, 2024
Data Sourced
via Launchpad·08:52 PM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·09:27 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-21596?
CVE-2020-21596 is a vulnerability in libde265 v1.0.4 that allows for a global buffer overflow in the decode_CABAC_bit function.
2
How severe is CVE-2020-21596?
CVE-2020-21596 has a severity score of 6.5, which is considered high.
3
How can CVE-2020-21596 be exploited?
CVE-2020-21596 can be exploited by utilizing a crafted file.
4
Which versions of libde265 are affected by CVE-2020-21596?
Versions 1.0.3-1 of libde265 are affected by CVE-2020-21596.
5
Where can I find more information about CVE-2020-21596?
You can find more information about CVE-2020-21596 on the Debian Security Tracker and the GitHub repository for libde265.