Skip to content

CVE-2024-1580

MEDIUM  |  Platform: iPadOS  |  Changelog

CVE Details

Description

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

CVSS 3.1 Score

MetricValue
Base Score5.9 (MEDIUM)
VectorCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

Weakness

References