Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-32570
HistoryMay 10, 2023 - 5:15 a.m.

CVE-2023-32570

2023-05-1005:15:12
Alpine Linux Development Team
security.alpinelinux.org
11
videolan
dav1d
1.2.0
thread_task.c
race condition
crash
unix

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.3%

VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.

OSVersionArchitecturePackageVersionFilename
Alpine3.17-mainnoarchdav1d= 1.0.0-r2UNKNOWN

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.3%