First published: Thu Sep 16 2021(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libde265 | 1.0.11-0+deb11u3 1.0.11-0+deb11u1 1.0.11-1+deb12u2 1.0.15-1 | |
libde265 | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-21603 is considered a critical vulnerability due to the presence of a heap buffer overflow that can lead to remote code execution.
To mitigate CVE-2020-21603, update the libde265 package to versions 1.0.11-0+deb11u3, 1.0.11-0+deb11u1, 1.0.11-1+deb12u2, or 1.0.15-1.
CVE-2020-21603 affects libde265 version 1.0.4 and earlier versions.
CVE-2020-21603 is characterized by a heap buffer overflow in the put_qpel_0_0_fallback_16 function.
Yes, CVE-2020-21603 can be exploited via a crafted file that triggers the underlying vulnerability.