Описание
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
Ссылки
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- Release Notes
- Release Notes
- Mailing List
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.0 (исключая)
cpe:2.3:a:videolan:dav1d:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 17.4.1 (исключая)Версия до 16.7.7 (исключая)Версия от 17.0 (включая) до 17.4.1 (исключая)Версия до 16.7.7 (исключая)Версия от 17.0 (включая) до 17.4.1 (исключая)Версия от 13.0 (включая) до 13.6.6 (исключая)Версия от 14.0 (включая) до 14.4.1 (исключая)Версия до 1.1.1 (исключая)
Одно из
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01835
Низкий
5.9 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-190
CWE-190
Связанные уязвимости
CVSS3: 5.9
ubuntu
больше 2 лет назад
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVSS3: 5.9
debian
больше 2 лет назад
An integer overflow in dav1d AV1 decoder that can occur when decoding ...
EPSS
Процентиль: 77%
0.01835
Низкий
5.9 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-190
CWE-190