libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/strukturag/libde265/issues/385 | patch issue tracking exploit |
https://lists.debian.org/debian-lts-announce/2023/03/msg00004.html | third party advisory mailing list |