CVE-2022-43237: Medium severity struktur libde265 vulnerability
Last updated 24 July 2024
Other sources
Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void putepelhvfallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libde265to a version that resolves this vulnerability.Fixed in 1.0.11-0+deb11u3Fixed in 1.0.11-0+deb11u1Fixed in 1.0.11-1+deb12u2Fixed in 1.0.15-1
Event History
Frequently Asked Questions
What is CVE-2022-43237?
CVE-2022-43237 is a stack-buffer-overflow vulnerability in Libde265 v1.0.8 that allows attackers to cause a Denial of Service (DoS) via a crafted video file.
What is the severity of CVE-2022-43237?
CVE-2022-43237 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2022-43237?
You can fix CVE-2022-43237 by updating the Libde265 package to version 1.0.11-0+deb10u4, 1.0.11-0+deb11u1, 1.0.11-1, or 1.0.12-2.
Where can I find more information about CVE-2022-43237?
You can find more information about CVE-2022-43237 on the GitHub issue page (https://github.com/strukturag/libde265/issues/344), the Debian Security Tracker (https://security-tracker.debian.org/tracker/CVE-2022-43237), and the Debian LTS announcement (https://lists.debian.org/debian-lts-announce/2023/01/msg00020.html).
What is the Common Weakness Enumeration (CWE) of CVE-2022-43237?
The Common Weakness Enumeration (CWE) of CVE-2022-43237 is CWE-787, which refers to the presence of a buffer overflow vulnerability.