CVE-2022-43238: Medium severity struktur libde265 vulnerability
Last updated 24 July 2024
Other sources
Libde265 v1.0.8 was discovered to contain an unknown crash via ffhevcputhevcqpelh3v3sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libde265to a version that resolves this vulnerability.Fixed in 1.0.11-0+deb11u3Fixed in 1.0.11-0+deb11u1Fixed in 1.0.11-1+deb12u2Fixed in 1.0.15-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-43238.
What is the severity of CVE-2022-43238?
The severity of CVE-2022-43238 is medium with a CVSS score of 6.5.
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers using a crafted video file to cause a Denial of Service (DoS) attack.
Which software versions are affected by CVE-2022-43238?
Libde265 version 1.0.8 is affected by this vulnerability.
How can I mitigate CVE-2022-43238?
To mitigate CVE-2022-43238, update to version 1.0.11-0+deb10u4, 1.0.11-0+deb11u1, 1.0.11-1, or 1.0.12-2 of the libde265 package.