CVE-2020-21603 PUBLISHED

libde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fallback_16 function, which can be exploited via a crafted a file.

EPSS 0.13% · 32.7th percentile

Risk Scores

EPSS Score
0.13%
32.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSlibde2650, 1.0.2-2build1
Ubuntu:Pro:16.04:LTSlibde2651.0.2-2, 0, 1.0.2-1build1
Ubuntu:20.04:LTSlibde2650, 1.0.3-1build1, 1.0.4-1

Timeline

References

Open in Interactive Console →