First published: Thu Jul 01 2021(Updated: )
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aomedia Libavif | =0.8.0 | |
Aomedia Libavif | =0.8.1 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36407 is a vulnerability in libavif 0.8.0 and 0.8.1 that allows an out-of-bounds write in avifDecoderDataFillImageGrid.
CVE-2020-36407 has a severity score of 8.8 out of 10, indicating a high severity.
libavif versions 0.8.0 and 0.8.1 are affected by CVE-2020-36407.
To fix CVE-2020-36407, you should update libavif to version 0.8.2 or later.
More information about CVE-2020-36407 can be found at the following references: [Reference 1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24811), [Reference 2](https://github.com/AOMediaCodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9), [Reference 3](https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libavif/OSV-2020-1597.yaml).