Re: [BLFS Trac] #23381: libde265-1.1.0

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23381: libde265-1.1.0
-------------------------+------------------------
 Reporter:  Bruce Dubbs  |       Owner:  blfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------
Changes (by Douglas R. Reno):

 * priority:  normal => high

Comment:

 {{{
 v1.1.0 - security limits

 Added de265_security_limits parameters to limit the maximum image size and
 memory that
 libde265 will use during decoding.

 Security fixes

     CVE TBD (GHSA-g2rg-wj66-w594) - Out-of-bounds write in
 process_reference_picture_set
 via predicted short-term RPS
     CVE TBD (GHSA-vv8h-932h-7r86) - Heap buffer overflow in
 de265_image_get_buffer via
 SPS dimension integer overflow
     CVE TBD (GHSA-g5hj-rf9f-7vxm) - Unbounded memory accumulation via
 orphaned slice
 headers in read_slice_NAL
     (GHSA-x27c-jp65-g395) - Quadratic CPU consumption in NAL parser
 (remove_stuffing_bytes, resize)
 }}}

 The only thing I can say professionally about GHSA-vv8h-932h-7r86 is:
 OUCH. "Massive heap buffer overflow (4 GB write into 1 KB allocation) —
 crash, high potential for code execution"
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23381#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.