CVE-2021-36410: Medium severity libde265 vulnerability
Published Jan 10, 2022
·Updated
A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function putepelhvfallback when running program dec265.
Affected Software
4 affected componentsFixes available
debian/libde265
1.0.11-0+deb11u31.0.11-0+deb11u11.0.11-1+deb12u21.0.15-1
struktur libde265=1.0.8
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Jan 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 8, 2024
Data Sourced
via Launchpad·05:18 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·05:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-36410?
CVE-2021-36410 is classified as a high severity vulnerability due to its nature as a stack-buffer overflow.
2
How do I fix CVE-2021-36410?
To mitigate CVE-2021-36410, upgrade libde265 to a version higher than 1.0.8, such as 1.0.11-0+deb11u3 or later.
3
What software is affected by CVE-2021-36410?
CVE-2021-36410 affects libde265 version 1.0.8.
4
What types of attacks can be executed due to CVE-2021-36410?
Exploitation of CVE-2021-36410 can potentially allow an attacker to execute arbitrary code or crash the affected application.
5
Is CVE-2021-36410 related to any specific operating systems?
CVE-2021-36410 is primarily relevant to Debian GNU/Linux versions 10.0 and 11.0.