dwauncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dccount is not strictly checked.
[
{
"digest": {
"line_hashes": [
"196709895360287458591615415705214410396",
"130380091940095792286365522484884190871",
"283493446620991118859812463275249449165",
"19386626409520732559976923280123000466",
"88974277760846921266435675601066312401",
"66708020939852844078050880899189869910",
"215846995322117982697734546612735061643"
],
"threshold": 0.9
},
"target": {
"file": "libavcodec/exr.c"
},
"signature_type": "Line",
"id": "CVE-2021-33815-92de094f",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/26d3c81bc5ef2f8c3f09d45eaeacfb4b1139a777",
"deprecated": false
},
{
"digest": {
"length": 5286.0,
"function_hash": "285466867490307915643097296913297550466"
},
"target": {
"file": "libavcodec/exr.c",
"function": "dwa_uncompress"
},
"signature_type": "Function",
"id": "CVE-2021-33815-d2c1e13a",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/26d3c81bc5ef2f8c3f09d45eaeacfb4b1139a777",
"deprecated": false
}
]