CVE for libdav1d-sys (#1895)

This commit is contained in:
Kalle Samuels
2024-02-19 09:15:45 -08:00
committed by GitHub
parent 99eb308ec5
commit 2d47fb6fcc

View File

@@ -0,0 +1,17 @@
```toml
[advisory]
id = "RUSTSEC-0000-0000"
package = "libdav1d-sys"
date = "2024-02-19"
url = "https://www.cvedetails.com/cve/CVE-2024-1580/"
categories = ["memory-corruption"]
keywords = ["integer-overflow"]
[affected]
[versions]
patched = [">= 0.7.0"]
```
# dav1d AV1 decoder integer overflow
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading to version 0.7.0 of libdav1d-sys, which includes dav1d 1.4.0