• [gentoo-announce] [ GLSA 202310-05 ] dav1d: Denial of Service

    From glsamaker@gentoo.org@21:1/5 to All on Sun Oct 8 07:50:01 2023
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202310-05
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Low
    Title: dav1d: Denial of Service
    Date: October 08, 2023
    Bugs: #906107
    ID: 202310-05

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    A vulnerability has been found in dav1d which could result in denial of service.

    Background
    ==========

    dav1d is an AV1 decoder.

    Affected packages
    =================

    Package Vulnerable Unaffected
    ---------------- ------------ ------------
    media-libs/dav1d < 1.2.0 >= 1.2.0

    Description
    ===========

    In some circumstances, dav1d might treat an invalid frame as valid,
    resulting in a crash.

    Impact
    ======

    Malformed frame data can result in a denial of service.

    Workaround
    ==========

    Users should avoid parsing untrusted video with dav1d.

    Resolution
    ==========

    All dav1d users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-libs/dav1d-1.2.0"

    References
    ==========

    [ 1 ] CVE-2023-32570
    https://nvd.nist.gov/vuln/detail/CVE-2023-32570

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202310-05

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2023 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmUiQUgACgkQFMQkOaVy +9nfrg//bYtdIR3KsmLpxZHskQZv0mzYjf05RQbJvqJ31VSqp1bZGRFoz2DZvXfk I9jBSGlhuPViDjJjILF4ByK3VJgFQCOXwK9ZWe/FtcOOINbwSyE/0tXTywsNrQbb L7Qvy08fh5YKEaXIM6LG3zqXDaajlNBK5hz/VBbLjz48YS9DmmkijDm772yt7xu2 FWLxXAdHzANHiiT0SbbpvHivX8Y8+rTfccGsvumpGNMxm+fng/tD4srpl6Zs1YX7 PUq1clCz/QxWrAlpv4sz6CIGhx8wbYW7ag9icxba76rN62asrWdT7rRtXrOpIXRf 4jxdrZ0WUfblUvTpGRiytmpWOOTQIgUbPRjWLPRVkR/ZRYQGoIuDXwn8YsZlBIMJ x9arzQEDxZHOIYNL+P5aCfQEurt/HJBa5MXjLscj/nj827u3zfLU1c54NVty6AXd u8M3LlnKe5zyzZlCNc5MrXU2uzh4qBq4PWTuzAXVABni8dP1Ika6VF8QvSeazzrM DwMDRDcaebnF3BGOSrBldmr6+BMbAPbBbyOniwMk7nZ9VP5pEZStGLkjM3sNtwbu 6wLE3hcL9ZnTqcwF9fTkDSoFCZ8C5sEpnQCSP3Awn89t2asAbOw+vI+9DePUQCGh cKFQEiMoxI3HdiEXENRGGufN/07Waf8NaOUyU5bu2o5gWJPRDHY=
    =SXl3
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)