logo

GHSA-mc39-h54g-pvw6 libdav1d-sys

Package

Manager: cargo
Name: libdav1d-sys
Vulnerable Version: >=0 <0.7.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

CVSS v4.0: CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

EPSS: N/A pctlN/A

Details

libdav1d-sys affected by dav1d AV1 decoder integer overflow An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading to version 0.7.0 of libdav1d-sys, which includes dav1d 1.4.0.

Metadata

Created: 2024-04-05T15:42:39Z
Modified: 2024-04-05T15:42:39Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json
CWE IDs: ["CWE-190"]
Alternative ID: N/A
Finding: F111
Auto approve: 1