strukturag libde265
cpe:2.3:a:struktur:libde265:*:*:*:*:*:*:*
- <d9fea9d
A segmentation fault vulnerability has been identified in strukturag libde265, specifically in commit d9fea9d. The issue arises within the 'decoder_context::compute_framedrop_table()' function, leading to a buffer overflow.
Exploitation of this vulnerability causes a segmentation fault, indicating a buffer overflow condition.
The vulnerability can be reproduced by compiling libde265 with AddressSanitizer enabled, using Clang as the compiler. After building the application, the 'dec265' tool can be run with a command-line argument that triggers the vulnerability, such as an invalid value for the 'T' parameter. This causes the application to attempt to access memory incorrectly, resulting in a segmentation fault.
Users are advised to update to the latest version of libde265, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.