CVE-2023-51792Stack-based Buffer Overflow in Libde265

Severity
3.3LOWNVD
EPSS
0.0%
top 96.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 7

Description

Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

debiandebian/libde265< libde265 1.0.13-1 (forky)
Debianstruktur/libde265< 1.0.13-1+1

🔴Vulnerability Details

2
GHSA
GHSA-xj57-m8w7-83wf: Buffer Overflow vulnerability in libde265 v12024-04-19
OSV
CVE-2023-51792: Buffer Overflow vulnerability in libde265 v12024-04-19

📋Vendor Advisories

2
Ubuntu
libde265 vulnerability2024-05-07
Debian
CVE-2023-51792: libde265 - Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cau...2023