CVE-2023-49465: High severity libde265 vulnerability
Published Dec 7, 2023
·Updated
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derivespatiallumavectorprediction function at motion.cc.
Affected Software
7 affected componentsFixes available
debian/libde265<=1.0.3-1, <=1.0.11-0+deb11u1
1.0.11-0+deb10u61.0.11-0+deb11u31.0.11-1+deb12u21.0.15-1
ubuntu/libde265<1.0.2-2ubuntu0.18.04.1~
1.0.2-2ubuntu0.18.04.1~
ubuntu/libde265<1.0.4-1ubuntu0.4
1.0.4-1ubuntu0.4
ubuntu/libde265<1.0.8-1ubuntu0.3
1.0.8-1ubuntu0.3
ubuntu/libde265<1.0.12-2ubuntu0.1
1.0.12-2ubuntu0.1
ubuntu/libde265<1.0.2-2ubuntu0.16.04.1~
1.0.2-2ubuntu0.16.04.1~
struktur libde265=1.0.14
Remediation
Patch Available
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Mar 5, 2024
Data Sourced
via Launchpad·10:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49465?
CVE-2023-49465 is classified as a heap-buffer-overflow vulnerability which can have critical implications if exploited.
2
How do I fix CVE-2023-49465?
To fix CVE-2023-49465, upgrade to a version of libde265 that is 1.0.11-0+deb10u6 or higher, or one of the specified remedial versions for your operating system.
3
Which versions of libde265 are affected by CVE-2023-49465?
Libde265 versions up to and including 1.0.14 are affected by CVE-2023-49465.
4
What systems are impacted by CVE-2023-49465?
CVE-2023-49465 impacts Debian and Ubuntu systems that have the vulnerable libde265 versions installed.
5
Is there a patch available for CVE-2023-49465?
Yes, a patch is available and users should upgrade to the remedial versions listed for their specific environment.