First published: Mon Feb 19 2024(Updated: )
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
Credit: cve-coordination@google.com Nick Galloway Google Project ZeroNick Galloway Google Project ZeroNick Galloway Google Project ZeroNick Galloway Google Project ZeroNick Galloway Google Project Zero
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <16.7.7 | 16.7.7 |
Apple iPadOS | <16.7.7 | 16.7.7 |
Apple macOS Sonoma | <14.4.1 | 14.4.1 |
Apple visionOS | <1.1.1 | 1.1.1 |
Apple macOS Ventura | <13.6.6 | 13.6.6 |
Apple iOS | <17.4.1 | 17.4.1 |
Apple iPadOS | <17.4.1 | 17.4.1 |
Apple Safari | <17.4.1 | 17.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)