CVE-2020-21603: Buffer Overflow
Published Sep 16, 2021
·Updated
Last updated 24 July 2024
Other sources
libde265 v1.0.4 contains a heap buffer overflow in the putqpel00fallback16 function, which can be exploited via a crafted a file.
Affected Software
2 affected componentsFixes available
debian/libde265
1.0.11-0+deb11u31.0.11-0+deb11u11.0.11-1+deb12u21.0.15-1
struktur libde265=1.0.4
Event History
Sep 16, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 30, 2024
Data Sourced
via Launchpad·08:52 PM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·09:27 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-21603?
CVE-2020-21603 is considered a critical vulnerability due to the presence of a heap buffer overflow that can lead to remote code execution.
2
How do I fix CVE-2020-21603?
To mitigate CVE-2020-21603, update the libde265 package to versions 1.0.11-0+deb11u3, 1.0.11-0+deb11u1, 1.0.11-1+deb12u2, or 1.0.15-1.
3
Which versions of libde265 are affected by CVE-2020-21603?
CVE-2020-21603 affects libde265 version 1.0.4 and earlier versions.
4
What is the nature of the vulnerability in CVE-2020-21603?
CVE-2020-21603 is characterized by a heap buffer overflow in the put_qpel_0_0_fallback_16 function.
5
Can I exploit CVE-2020-21603 through file manipulation?
Yes, CVE-2020-21603 can be exploited via a crafted file that triggers the underlying vulnerability.