Multiple security issues were discovered in libde265, an implementation of
the H265 video codec which may result in denial of service and potentially
the execution of arbitrary code if a malformed media file is processed
For the stable distribution (bullseye), these problems have been fixed in
version 1011-0+deb11u1
We recommend that you upgra ...
CVE-2020-21600 Exploit
libde265 v104 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file
Windows Binary PoC
/CVE-2020-21600exe will run the exploit
/CVE-2020-21600exe -t Target IP
/CVE-2020-21600exe -t wwwexamplecom
Running the exploit on Linux
Change t
CVE-2020-21600
libde265 v104 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file
authentication
complexity
vector
NONE
MEDIUM
NETWORK
confidentiality
integrity
availability
NONE
NONE
PARTIAL
CVSS Score: 43
References
strukturag/libde265#243
cwemitreorg/data/definitio
CVE-2020-21600 Exploit
libde265 v104 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file
Windows Binary PoC
/CVE-2020-21600exe will run the exploit
/CVE-2020-21600exe -t Target IP
/CVE-2020-21600exe -t wwwexamplecom
Running the exploit on Linux
Change t