CVE-2022-43250: Medium severity struktur libde265 vulnerability
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via putqpel00fallback16 in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libde265to a version that resolves this vulnerability.Fixed in 1.0.11-0+deb10u6Fixed in 1.0.11-0+deb11u3Fixed in 1.0.11-0+deb11u1Fixed in 1.0.11-1+deb12u2Fixed in 1.0.15-1 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.2-2ubuntu0.18.04.1~ - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.4-1ubuntu0.3 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.8-1ubuntu0.2 - Upgrade
Upgrade
ubuntu/libde265to a version that resolves this vulnerability.Fixed in 1.0.2-2ubuntu0.16.04.1~
Event History
Frequently Asked Questions
What is CVE-2022-43250?
CVE-2022-43250 is a heap-buffer-overflow vulnerability in Libde265 v1.0.8.
How can the CVE-2022-43250 vulnerability be exploited?
The CVE-2022-43250 vulnerability can be exploited by attackers using a crafted video file.
What is the impact of the CVE-2022-43250 vulnerability?
The impact of the CVE-2022-43250 vulnerability is a Denial of Service (DoS) attack.
Which versions of Libde265 are affected by CVE-2022-43250?
Versions up to and including 1.0.8 of Libde265 are affected by CVE-2022-43250.
How can I fix the CVE-2022-43250 vulnerability?
To fix the CVE-2022-43250 vulnerability, update Libde265 to version 1.0.11-0+deb10u4, 1.0.11-0+deb11u1, 1.0.11-1, or 1.0.12-1.