CVE-2023-24754: Null Pointer Dereference
Published Mar 1, 2023
·Updated
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ffhevcputweightedpredavg8sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
Affected Software
8 affected componentsFixes available
debian/libde265<=1.0.3-1
1.0.11-0+deb10u61.0.11-0+deb11u31.0.11-0+deb11u11.0.11-1+deb12u21.0.15-1
ubuntu/libde265<1.0.2-2ubuntu0.18.04.1~
1.0.2-2ubuntu0.18.04.1~
ubuntu/libde265<1.0.4-1ubuntu0.3
1.0.4-1ubuntu0.3
ubuntu/libde265<1.0.8-1ubuntu0.2
1.0.8-1ubuntu0.2
ubuntu/libde265<1.0.11-1
1.0.11-1
ubuntu/libde265<1.0.2-2ubuntu0.16.04.1~
1.0.2-2ubuntu0.16.04.1~
struktur libde265=1.0.10
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 26, 2024
Data Sourced
via Launchpad·09:11 PM
Description
Frequently Asked Questions
1
What is CVE-2023-24754?
CVE-2023-24754 is a vulnerability in libde265 v1.0.10 that allows attackers to cause a denial of service (DoS) via a crafted input file.
2
What is the severity of CVE-2023-24754?
The severity of CVE-2023-24754 is medium, with a severity value of 5.5.
3
How does CVE-2023-24754 affect libde265?
CVE-2023-24754 affects libde265 v1.0.10, specifically the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc.
4
How can an attacker exploit CVE-2023-24754?
An attacker can exploit CVE-2023-24754 by providing a specially crafted input file.
5
Is there a fix available for CVE-2023-24754?
Yes, a fix for CVE-2023-24754 is available. Please refer to the provided references for more information.