CVE-2021-36411: Medium severity libde265 vulnerability
An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function deriveboundaryStrength of deblock.cc has occurred. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36411?
CVE-2021-36411 is a vulnerability in libde265 v1.0.8 that allows incorrect access control, leading to a segmentation fault and application crash.
What is the severity of CVE-2021-36411?
The severity of CVE-2021-36411 is medium, with a CVSS severity score of 5.5.
How does CVE-2021-36411 impact the affected software?
CVE-2021-36411 causes a segmentation fault and application crash, resulting in remote denial of service.
Which software versions are affected by CVE-2021-36411?
The vulnerability affects libde265 v1.0.8, as well as Struktur Libde265 1.0.8, Debian Debian Linux 10.0, and Debian Debian Linux 11.0.
How can CVE-2021-36411 be fixed?
To fix CVE-2021-36411, update the libde265 package to version 1.0.11-0+deb10u4, 1.0.11-0+deb11u1, 1.0.11-1, or 1.0.12-2.