CVE-2024-1580
Integer overflow in VideoLAN dav1d
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 1.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Affected products
VideoLAN · dav1dWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://code.videolan.org/videolan/dav1d/-/blob/master/NEWShttps://code.videolan.org/videolan/dav1d/-/releases/1.4.0http://seclists.org/fulldisclosure/2024/Mar/36http://seclists.org/fulldisclosure/2024/Mar/37http://seclists.org/fulldisclosure/2024/Mar/38http://seclists.org/fulldisclosure/2024/Mar/39http://seclists.org/fulldisclosure/2024/Mar/40http://seclists.org/fulldisclosure/2024/Mar/41https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/https://support.apple.com/kb/HT214093https://support.apple.com/kb/HT214094https://support.apple.com/kb/HT214095