libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
[
{
"deprecated": false,
"target": {
"file": "src/read.c"
},
"signature_type": "Line",
"source": "https://github.com/aomediacodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9",
"digest": {
"threshold": 0.9,
"line_hashes": [
"141426086229260369640137979938983474898",
"86606388548066116302343634120139353619",
"129706273375831142077064862974063230480",
"228291883178495089287266741724136130496"
]
},
"id": "CVE-2020-36407-1dd64457",
"signature_version": "v1"
},
{
"deprecated": false,
"target": {
"function": "avifParseImageGridBox",
"file": "src/read.c"
},
"signature_type": "Function",
"source": "https://github.com/aomediacodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9",
"digest": {
"function_hash": "284186746123024602770776359937458765098",
"length": 811.0
},
"id": "CVE-2020-36407-4024d1d0",
"signature_version": "v1"
}
]