CVE-2023-51792

Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
mitreCNA
---
---
CISA-ADPADP
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Debian logo
Debian Releases
Debian Product
Codename
libde265
bullseye
no-dsa
bookworm
no-dsa
buster
postponed
bullseye (security)
vulnerable
sid
1.0.15-1
fixed
trixie
1.0.15-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libde265
oracular
not-affected
noble
not-affected
mantic
Fixed 1.0.12-2ubuntu0.2
released
jammy
Fixed 1.0.8-1ubuntu0.3+esm1
released
focal
Fixed 1.0.4-1ubuntu0.4+esm1
released
bionic
Fixed 1.0.2-2ubuntu0.18.04.1~esm5
released
xenial
Fixed 1.0.2-2ubuntu0.16.04.1~esm5
released