CVE-2023-27102: Null Pointer Dereference
Published Mar 15, 2023
·Updated
Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decodercontext::processslicesegmentheader at decctx.cc.
Affected Software
6 affected componentsFixes available
debian/libde265<=1.0.3-1, <=1.0.11-0+deb11u1
1.0.11-0+deb10u61.0.11-0+deb11u31.0.11-1+deb12u21.0.15-1
ubuntu/libde265<1.0.2-2ubuntu0.18.04.1~
1.0.2-2ubuntu0.18.04.1~
ubuntu/libde265<1.0.4-1ubuntu0.4
1.0.4-1ubuntu0.4
ubuntu/libde265<1.0.8-1ubuntu0.3
1.0.8-1ubuntu0.3
ubuntu/libde265<1.0.2-2ubuntu0.16.04.1~
1.0.2-2ubuntu0.16.04.1~
struktur libde265=1.0.11
Event History
Mar 15, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Mar 5, 2024
Data Sourced
via Launchpad·10:35 PM
Description
Frequently Asked Questions
1
What is CVE-2023-27102?
CVE-2023-27102 is a vulnerability in Libde265 v1.0.11 that allows for a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc.
2
What is the severity of CVE-2023-27102?
The severity of CVE-2023-27102 is medium with a CVSS score of 6.5.
3
Which software version is affected by CVE-2023-27102?
The Libde265 version 1.0.11 is affected by CVE-2023-27102.
4
How can I fix CVE-2023-27102?
To fix CVE-2023-27102, it is recommended to update Libde265 to a patched version provided by the vendor.
5
Where can I find more information about CVE-2023-27102?
More information about CVE-2023-27102 can be found at the following reference: [GitHub Issue](https://github.com/strukturag/libde265/issues/393).