CVE-2024-1580

SOURCE - nist

Summary

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

EPSS Score: 0.00046 (0.165)

Common Weakness Enumeration (CWE)

SOURCE - nist

Integer Overflow or Wraparound


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/dav1ddebdebianunstable<1.4.0-11.4.0-1
debian/dav1ddebdebian12<1.0.0-2+deb12u11.0.0-2+deb12u1
debian/dav1ddebdebian13<1.4.0-11.4.0-1
debian/dav1ddebdebian11<0.7.1-3+deb11u10.7.1-3+deb11u1

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

1.2


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.9medium

alpine

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium