First published: Thu Dec 07 2023(Updated: )
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libde265 | <=1.0.3-1<=1.0.11-0+deb11u1 | 1.0.11-0+deb10u6 1.0.11-0+deb11u3 1.0.11-1+deb12u2 1.0.15-1 |
ubuntu/libde265 | <1.0.2-2ubuntu0.18.04.1~ | 1.0.2-2ubuntu0.18.04.1~ |
ubuntu/libde265 | <1.0.4-1ubuntu0.4 | 1.0.4-1ubuntu0.4 |
ubuntu/libde265 | <1.0.8-1ubuntu0.3 | 1.0.8-1ubuntu0.3 |
ubuntu/libde265 | <1.0.12-2ubuntu0.1 | 1.0.12-2ubuntu0.1 |
ubuntu/libde265 | <1.0.2-2ubuntu0.16.04.1~ | 1.0.2-2ubuntu0.16.04.1~ |
Struktur libde265 | =1.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49465 is classified as a heap-buffer-overflow vulnerability which can have critical implications if exploited.
To fix CVE-2023-49465, upgrade to a version of libde265 that is 1.0.11-0+deb10u6 or higher, or one of the specified remedial versions for your operating system.
Libde265 versions up to and including 1.0.14 are affected by CVE-2023-49465.
CVE-2023-49465 impacts Debian and Ubuntu systems that have the vulnerable libde265 versions installed.
Yes, a patch is available and users should upgrade to the remedial versions listed for their specific environment.