Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-38949

Published: 26 June 2024

Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc

Notes

AuthorNote
mdeslaur
as of 2024-07-05, there is no fix available from libde265
developers

Priority

Medium

Status

Package Release Status
libde265
Launchpad, Ubuntu, Debian
bionic Deferred
(2024-07-05)
focal Deferred
(2024-07-05)
jammy Deferred
(2024-07-05)
mantic Ignored
(end of life, was deferred [2024-07-05])
noble Deferred
(2024-07-05)
upstream Needs triage

xenial Deferred
(2024-07-05)