track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
[
{
"digest": {
"function_hash": "10276585309990227696075281458891561069",
"length": 3384.0
},
"id": "CVE-2020-35964-0f156ff9",
"target": {
"function": "track_header",
"file": "libavformat/vividas.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/27a99e2c7d450fef15594671eef4465c8a166bd7",
"signature_type": "Function"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"525220999456771788212427340728994532",
"317307677012499269104552687143356229094",
"176363839622445295858762660691841516745",
"43016194688168285533120225362894370751",
"286042928014928739281680011525269130541",
"11992140142306964629683768603922020439",
"200843498105875523833003801902439723737",
"39197240954016635089876379214511819819",
"281417731946186976767554153478378754190",
"203532130500819324495404539649090814028",
"304080042666092356809505296181497057150",
"226802671110702742982797614535487385524",
"73082539325848717179228355520517924855",
"79775762244740831969228940730835702535",
"143250374037328722978253924629184378451",
"176687105145931248001790678730593095432",
"114681025252844250937220800945534023486",
"37486818162621233002606144904404698805",
"166262640446944194489426637763137381045",
"319702081660647726261688445969219196991",
"215814048822915231723972422777677205668"
]
},
"id": "CVE-2020-35964-ee6b3729",
"target": {
"file": "libavformat/vividas.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/27a99e2c7d450fef15594671eef4465c8a166bd7",
"signature_type": "Line"
}
]