CVE-2023-24758: Null Pointer Dereference
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ffhevcputweightedpredavg8sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-24758.
What is the severity of CVE-2023-24758?
The severity of CVE-2023-24758 is medium with a CVSS score of 5.5.
What software versions are affected by CVE-2023-24758?
libde265 v1.0.10 is affected by CVE-2023-24758.
How can CVE-2023-24758 be exploited?
CVE-2023-24758 can be exploited by attackers using a crafted input file, leading to a Denial of Service (DoS) attack.
Are there any references available for CVE-2023-24758?
Yes, you can find references for CVE-2023-24758 at the following links: [https://github.com/strukturag/libde265/issues/383](https://github.com/strukturag/libde265/issues/383) and [https://lists.debian.org/debian-lts-announce/2023/03/msg00004.html](https://lists.debian.org/debian-lts-announce/2023/03/msg00004.html).