CVE-2024-1580
Integer overflow in VideoLAN dav1d
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.9EPSS 1.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
19 feb 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Productos afectados
VideoLAN · dav1d¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://code.videolan.org/videolan/dav1d/-/blob/master/NEWShttps://code.videolan.org/videolan/dav1d/-/releases/1.4.0http://seclists.org/fulldisclosure/2024/Mar/36http://seclists.org/fulldisclosure/2024/Mar/37http://seclists.org/fulldisclosure/2024/Mar/38http://seclists.org/fulldisclosure/2024/Mar/39http://seclists.org/fulldisclosure/2024/Mar/40http://seclists.org/fulldisclosure/2024/Mar/41https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/https://support.apple.com/kb/HT214093https://support.apple.com/kb/HT214094https://support.apple.com/kb/HT214095