Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the numtilecolumns and numtilerow parameters in the function picparameterset::dump.
[
{
"id": "CVE-2023-43887-33eaefc0",
"digest": {
"function_hash": "115318745234840897845172318388566652946",
"length": 468.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/strukturag/libde265/commit/63b596c915977f038eafd7647d1db25488a8c133",
"target": {
"function": "decoder_context::read_pps_NAL",
"file": "libde265/decctx.cc"
},
"signature_version": "v1"
},
{
"id": "CVE-2023-43887-af066c82",
"digest": {
"line_hashes": [
"145631099459763226381212929949972107850",
"329025106158059296245517650606473879127",
"224877373758412648504169160339250263469",
"33325110550459107806935975561007447492",
"67677560191946787987919874293443464310",
"150421879833117031061740108422218256599",
"313785268145090874383446176971876695378",
"53004177848232812490147634192017942808",
"240418118779755308749764802555398091281",
"194908936974693031164250873985602853148",
"122689502183537620170736254362945799620"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/strukturag/libde265/commit/63b596c915977f038eafd7647d1db25488a8c133",
"target": {
"file": "libde265/decctx.cc"
},
"signature_version": "v1"
}
]