CVE-2022-43245: Medium severity struktur libde265 vulnerability
Libde265 v1.0.8 was discovered to contain a segmentation violation via applysaointernal<unsigned short> in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libde265to a version that resolves this vulnerability.Fixed in 1.0.11-0+deb10u6Fixed in 1.0.11-0+deb11u3Fixed in 1.0.11-0+deb11u1Fixed in 1.0.11-1+deb12u2Fixed in 1.0.15-1 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.2-2ubuntu0.18.04.1~ - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.4-1ubuntu0.3 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.8-1ubuntu0.2 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.2-2ubuntu0.16.04.1~
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43245?
The severity of CVE-2022-43245 is high with a CVSS score of 6.5.
How can attackers exploit CVE-2022-43245?
Attackers can exploit CVE-2022-43245 by crafting a malicious video file to cause a denial of service (DoS) attack.
What is the affected software of CVE-2022-43245?
The affected software of CVE-2022-43245 includes Libde265 v1.0.8 and certain versions of Debian Debian Linux.
How can I fix CVE-2022-43245?
To fix CVE-2022-43245, it is recommended to update to the patched versions of Libde265, such as 1.0.11-0+deb10u4 or 1.0.11-0+deb11u1.
Where can I find more information about CVE-2022-43245?
You can find more information about CVE-2022-43245 on the Debian Security Tracker and the GitHub repository of Libde265.