CVE-2020-21605: Medium severity libde265 vulnerability
Published Sep 16, 2021
·Updated
Last updated 24 July 2024
Other sources
libde265 v1.0.4 contains a segmentation fault in the applysaointernal function, which can be exploited via a crafted a file.
Affected Software
2 affected componentsFixes available
debian/libde265
1.0.11-0+deb11u31.0.11-0+deb11u11.0.11-1+deb12u21.0.15-1
struktur libde265=1.0.4
Event History
Sep 16, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 30, 2024
Data Sourced
via Launchpad·08:52 PM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·09:27 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-21605?
CVE-2020-21605 is a vulnerability in libde265 v1.0.4 that allows an attacker to trigger a segmentation fault via a crafted file.
2
How can CVE-2020-21605 be exploited?
CVE-2020-21605 can be exploited by sending a specially crafted file to a vulnerable libde265 v1.0.4 application, causing a segmentation fault.
3
What is the severity of CVE-2020-21605?
The severity of CVE-2020-21605 is medium with a CVSS score of 6.5.
4
Which software versions are affected by CVE-2020-21605?
The affected versions of libde265 are 1.0.3-1, 1.0.4, 1.0.11-0+deb10u4, 1.0.11-0+deb11u1, 1.0.11-1, and 1.0.12-2.
5
How can I fix CVE-2020-21605?
To fix CVE-2020-21605, update libde265 to a version equal to or later than 1.0.11-0+deb10u4, 1.0.11-0+deb11u1, 1.0.11-1, or 1.0.12-2.