libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
{ "vanir_signatures": [ { "source": "https://github.com/aomediacodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9", "signature_version": "v1", "deprecated": false, "id": "CVE-2020-36407-1dd64457", "target": { "file": "src/read.c" }, "digest": { "line_hashes": [ "141426086229260369640137979938983474898", "86606388548066116302343634120139353619", "129706273375831142077064862974063230480", "228291883178495089287266741724136130496" ], "threshold": 0.9 }, "signature_type": "Line" }, { "source": "https://github.com/aomediacodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9", "signature_version": "v1", "deprecated": false, "id": "CVE-2020-36407-4024d1d0", "target": { "file": "src/read.c", "function": "avifParseImageGridBox" }, "digest": { "function_hash": "284186746123024602770776359937458765098", "length": 811.0 }, "signature_type": "Function" } ] }