CVE-2020-21600 PUBLISHED

libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file.

EPSS 0.18% · 38.8th percentile

Risk Scores

EPSS Score
0.18%
38.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlibde2650, 1.0.2-1build1, 1.0.2-2
Ubuntu:20.04:LTSlibde2650, 1.0.4-1, 1.0.4-1build1
Ubuntu:Pro:18.04:LTSlibde2651.0.2-2build1, 0

Timeline

References

Open in Interactive Console →