CVE-2023-24756: Null Pointer Dereference
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ffhevcputunweightedpred8sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-24756?
CVE-2023-24756 is a vulnerability in libde265 v1.0.10 that allows attackers to cause a Denial of Service (DoS) via a crafted input file.
What is the severity of CVE-2023-24756?
CVE-2023-24756 has a severity rating of medium with a CVSS score of 5.5.
How does CVE-2023-24756 impact Struktur Libde265 v1.0.10?
CVE-2023-24756 impacts Struktur Libde265 v1.0.10 by allowing attackers to cause a Denial of Service (DoS) via a crafted input file.
How does CVE-2023-24756 impact Debian Debian Linux 10.0?
CVE-2023-24756 impacts Debian Debian Linux 10.0 by allowing attackers to cause a Denial of Service (DoS) via a crafted input file.
How do I fix CVE-2023-24756 in libde265 v1.0.10?
To fix CVE-2023-24756 in libde265 v1.0.10, it is recommended to update to the latest version of the software.
Where can I find more information about CVE-2023-24756?
More information about CVE-2023-24756 can be found at the following references: [link1](https://github.com/strukturag/libde265/issues/380), [link2](https://lists.debian.org/debian-lts-announce/2023/03/msg00004.html).