mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
116 lines
3.6 KiB
JSON
116 lines
3.6 KiB
JSON
{
|
|
"id": "CVE-2024-1580",
|
|
"sourceIdentifier": "cve-coordination@google.com",
|
|
"published": "2024-02-19T11:15:08.817",
|
|
"lastModified": "2024-03-27T18:15:09.063",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.\n\n\n\n"
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Un desbordamiento de enteros en el decodificador dav1d AV1 que puede ocurrir al decodificar videos con un tama\u00f1o de cuadro grande. Esto puede provocar da\u00f1os en la memoria del decodificador AV1. Recomendamos actualizar la versi\u00f3n anterior 1.4.0 de dav1d."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "cve-coordination@google.com",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L",
|
|
"attackVector": "ADJACENT_NETWORK",
|
|
"attackComplexity": "HIGH",
|
|
"privilegesRequired": "LOW",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "LOW",
|
|
"baseScore": 5.9,
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
"exploitabilityScore": 1.2,
|
|
"impactScore": 4.7
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "cve-coordination@google.com",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-190"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2024/Mar/36",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2024/Mar/37",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2024/Mar/38",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2024/Mar/39",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2024/Mar/40",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2024/Mar/41",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://code.videolan.org/videolan/dav1d/-/releases/1.4.0",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/kb/HT214093",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/kb/HT214094",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/kb/HT214095",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/kb/HT214096",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/kb/HT214097",
|
|
"source": "cve-coordination@google.com"
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/kb/HT214098",
|
|
"source": "cve-coordination@google.com"
|
|
}
|
|
]
|
|
} |