First published: Mon Jan 10 2022(Updated: )
A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libde265 | 1.0.11-0+deb11u3 1.0.11-0+deb11u1 1.0.11-1+deb12u2 1.0.15-1 | |
libde265 | =1.0.8 | |
Debian Linux | =10.0 | |
Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36410 is classified as a high severity vulnerability due to its nature as a stack-buffer overflow.
To mitigate CVE-2021-36410, upgrade libde265 to a version higher than 1.0.8, such as 1.0.11-0+deb11u3 or later.
CVE-2021-36410 affects libde265 version 1.0.8.
Exploitation of CVE-2021-36410 can potentially allow an attacker to execute arbitrary code or crash the affected application.
CVE-2021-36410 is primarily relevant to Debian GNU/Linux versions 10.0 and 11.0.