Bugzilla – Bug 1187918
VUL-1: CVE-2020-36407: libavif: out-of-bounds write in avifDecoderDataFillImageGrid()
Last modified: 2021-07-01 12:05:51 UTC
CVE-2020-36407 libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-36407 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24811 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36407 https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libavif/OSV-2020-1597.yaml https://github.com/AOMediaCodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9
not relevant, we are on 0.9.x everywhere. closing.