CVE-2024-1580
HIGH8.8EPSS 0.58%dav1d - security update
發布日:2024/2/19修改日:2025/11/19
也稱為:ALPINE-CVE-2024-1580
描述
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
受影響套件(3)
- Alpine/dav1dfrom 0, < 1.3.0-r1
- Debian/dav1dfrom 0, < 0.7.1-3+deb11u1
- Debian/dav1dfrom 0, < 0.7.1-3+deb11u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |