There is a heap-based buffer overflow in the function hpelmotion in mpegvideomotion.c in libav 12.1. A crafted input can lead to a remote denial of service attack.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9987.json"