ALT-PU-2024-4636-4
Closed vulnerabilities
Published: 2024-07-01
Modified: 2026-01-20
Modified: 2026-01-20
BDU:2024-04901
Уязвимость декодера dav1d операционных систем iOS, iPadOS, visionOS, macOS, Fedora, браузера Safari, позволяющая нарушителю выполнить произвольный код
Severity: MEDIUM (5.9)Vector: AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Severity: MEDIUM (5.5)Vector: AV:A/AC:H/Au:S/C:P/I:C/A:P
References:
Published: 2023-05-10
Modified: 2025-01-28
Modified: 2025-01-28
CVE-2023-32570
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.
Severity: MEDIUM (5.9)Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- https://code.videolan.org/videolan/dav1d/-/commit/cf617fdae0b9bfabd27282854c8e81450d955efa
- https://code.videolan.org/videolan/dav1d/-/tags/1.2.0
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WGSO7UMOF4MVLQ5H6KIV7OG6ONS377B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXZ6CUNJFDJLCFOZHY2TIGMCAEITLCRP/
- https://security.gentoo.org/glsa/202310-05
- https://code.videolan.org/videolan/dav1d/-/commit/cf617fdae0b9bfabd27282854c8e81450d955efa
- https://code.videolan.org/videolan/dav1d/-/tags/1.2.0
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WGSO7UMOF4MVLQ5H6KIV7OG6ONS377B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXZ6CUNJFDJLCFOZHY2TIGMCAEITLCRP/
- https://security.gentoo.org/glsa/202310-05
Published: 2024-02-19
Modified: 2025-02-13
Modified: 2025-02-13
CVE-2024-1580
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
Severity: HIGH (8.8)Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- http://seclists.org/fulldisclosure/2024/Mar/36
- http://seclists.org/fulldisclosure/2024/Mar/37
- http://seclists.org/fulldisclosure/2024/Mar/38
- http://seclists.org/fulldisclosure/2024/Mar/39
- http://seclists.org/fulldisclosure/2024/Mar/40
- http://seclists.org/fulldisclosure/2024/Mar/41
- https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS
- https://code.videolan.org/videolan/dav1d/-/releases/1.4.0
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/
- https://support.apple.com/kb/HT214093
- https://support.apple.com/kb/HT214094
- https://support.apple.com/kb/HT214095
- https://support.apple.com/kb/HT214096
- https://support.apple.com/kb/HT214097
- https://support.apple.com/kb/HT214098
- http://seclists.org/fulldisclosure/2024/Mar/36
- http://seclists.org/fulldisclosure/2024/Mar/37
- http://seclists.org/fulldisclosure/2024/Mar/38
- http://seclists.org/fulldisclosure/2024/Mar/39
- http://seclists.org/fulldisclosure/2024/Mar/40
- http://seclists.org/fulldisclosure/2024/Mar/41
- https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS
- https://code.videolan.org/videolan/dav1d/-/releases/1.4.0
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/
- https://support.apple.com/kb/HT214093
- https://support.apple.com/kb/HT214094
- https://support.apple.com/kb/HT214095
- https://support.apple.com/kb/HT214096
- https://support.apple.com/kb/HT214097
- https://support.apple.com/kb/HT214098
