ZeroHour

CVE-2024-1580

CVSS 3.1
8.8 high
EPSS
2%p78
Published
()
Modified
Description

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

Vendors
videolanapplefedoraproject
Products
dav1d, safari, ipados, iphone os, macos, visionos, fedora
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.