An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5686-1 | dav1d security update |
EUVD |
EUVD-2024-17324 | An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d. | An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d. |
Thu, 23 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ipados Apple iphone Os Apple macos Apple safari Apple visionos Fedoraproject Fedoraproject fedora Videolan Videolan dav1d |
|
| CPEs | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:a:videolan:dav1d:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple ipados Apple iphone Os Apple macos Apple safari Apple visionos Fedoraproject Fedoraproject fedora Videolan Videolan dav1d |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-02-13T17:32:17.584Z
Reserved: 2024-02-16T12:23:14.335Z
Link: CVE-2024-1580
Updated: 2024-08-01T18:40:21.411Z
Status : Modified
Published: 2024-02-19T11:15:08.817
Modified: 2025-02-13T18:16:25.577
Link: CVE-2024-1580
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD