CVE-2022-43244: Medium severity struktur libde265 vulnerability
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via putqpelfallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libde265to a version that resolves this vulnerability.Fixed in 1.0.11-0+deb10u6Fixed in 1.0.11-0+deb11u3Fixed in 1.0.11-0+deb11u1Fixed in 1.0.11-1+deb12u2Fixed in 1.0.15-1 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.2-2ubuntu0.18.04.1~ - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.4-1ubuntu0.3 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.8-1ubuntu0.2 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.2-2ubuntu0.16.04.1~
Event History
Frequently Asked Questions
What is CVE-2022-43244?
CVE-2022-43244 is a heap-buffer-overflow vulnerability in Libde265 v1.0.8 that can result in a Denial of Service (DoS) by using a crafted video file.
What is the severity of CVE-2022-43244?
The severity of CVE-2022-43244 is high as it allows attackers to cause a Denial of Service (DoS) attack.
How does CVE-2022-43244 impact Libde265 v1.0.8?
CVE-2022-43244 impacts Libde265 v1.0.8 by enabling a heap-buffer-overflow vulnerability, allowing attackers to trigger a Denial of Service (DoS) through a specially crafted video file.
How can I mitigate CVE-2022-43244?
To mitigate CVE-2022-43244, update to a version of Libde265 that includes the remedy, such as 1.0.11-0+deb10u4, 1.0.11-0+deb11u1, 1.0.11-1, or 1.0.12-1.
Where can I find more information about CVE-2022-43244?
You can find more information about CVE-2022-43244 on the following references: [GitHub issue](https://github.com/strukturag/libde265/issues/342) and [Debian security tracker](https://security-tracker.debian.org/tracker/CVE-2022-43244).