mirror of
https://github.com/OMGeeky/advisory-db.git
synced 2025-12-27 06:29:31 +01:00
CVE for libdav1d-sys (#1895)
This commit is contained in:
17
crates/libdav1d-sys/RUSTSEC-0000-0000.md
Normal file
17
crates/libdav1d-sys/RUSTSEC-0000-0000.md
Normal file
@@ -0,0 +1,17 @@
|
||||
```toml
|
||||
[advisory]
|
||||
id = "RUSTSEC-0000-0000"
|
||||
package = "libdav1d-sys"
|
||||
date = "2024-02-19"
|
||||
url = "https://www.cvedetails.com/cve/CVE-2024-1580/"
|
||||
categories = ["memory-corruption"]
|
||||
keywords = ["integer-overflow"]
|
||||
|
||||
[affected]
|
||||
[versions]
|
||||
patched = [">= 0.7.0"]
|
||||
```
|
||||
|
||||
# dav1d AV1 decoder integer overflow
|
||||
|
||||
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading to version 0.7.0 of libdav1d-sys, which includes dav1d 1.4.0
|
||||
Reference in New Issue
Block a user