CVE-2024-1580

HIGH8.8EPSS 0.58%

dav1d - security update

發布日:2024/2/19修改日:2025/11/19
也稱為:ALPINE-CVE-2024-1580

描述

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(2)