rav1e is vulnerable to Integer Overflow
19
Low Risk
Affected versions of this package are vulnerable to a bit overflow when writing headers. In these functions, the call to bw.write(5, 31) e.g. attempts to write the signed integer 31 using only 5 bits, which is insufficient due to the sign bit requirement. This can result in incorrect header encoding and potentially unpredictable behavior.
You are affected if you are using a version that falls within the vulnerable range.
rav1e is vulnerable to Integer Overflow in versions 0.8.0 - 0.8.0.
Upgrade the rav1e library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant