« Volver al listado

CVE-2024-1580

Estado: ModificadaAlta (8.8)—

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-1580",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-1580",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-26T15:24:40.372465Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "repo": "https://code.videolan.org/videolan/dav1d",
          "vendor": "VideoLAN",
          "product": "dav1d",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.4.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-19T11:15:08.817",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/36",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/37",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/38",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/39",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/40",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/41",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS",
      "tags": [
        "Release Notes"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://code.videolan.org/videolan/dav1d/-/releases/1.4.0",
      "tags": [
        "Release Notes"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://support.apple.com/kb/HT214093",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://support.apple.com/kb/HT214094",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://support.apple.com/kb/HT214095",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://support.apple.com/kb/HT214096",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://support.apple.com/kb/HT214097",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://support.apple.com/kb/HT214098",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/36",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/37",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/38",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/39",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/40",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/41",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://code.videolan.org/videolan/dav1d/-/releases/1.4.0",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214093",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214094",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214095",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214096",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214097",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214098",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d."
    },
    {
      "lang": "es",
      "value": "Un desbordamiento de enteros en el decodificador dav1d AV1 que puede ocurrir al decodificar videos con un tamaño de cuadro grande. Esto puede provocar daños en la memoria del decodificador AV1. Recomendamos actualizar la versión anterior 1.4.0 de dav1d."
    }
  ],
  "lastModified": "2026-06-17T07:04:34.387",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:videolan:dav1d:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B21FACDB-790F-4BDF-AE54-72C70D1880C0",
              "versionEndExcluding": "1.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B0BD32E-FA45-4796-956D-D1F2C049171E",
              "versionEndExcluding": "17.4.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35B07242-1592-4814-8866-FA7DA2021DDC",
              "versionEndExcluding": "16.7.7"
            },
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "027265B2-C0CD-46D8-BF40-5E591CFDE9D6",
              "versionEndExcluding": "17.4.1",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4450D591-7B62-4339-9F0F-08C51F701967",
              "versionEndExcluding": "16.7.7"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AA95646-94B7-4C20-9B69-371409BA4E22",
              "versionEndExcluding": "17.4.1",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55A1512B-3C9A-428C-97BD-B3B6813B150D",
              "versionEndExcluding": "13.6.6",
              "versionStartIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "580B86E1-BCC1-419C-86B7-2A33DA257401",
              "versionEndExcluding": "14.4.1",
              "versionStartIncluding": "14.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8418E27-11BA-4DE1-9596-6E88F5A9C052",
              "versionEndExcluding": "1.1.1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA277A6C-83EC-4536-9125-97B84C4FAF59"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}