CVE-2020-36407: High severity fedora libavif vulnerability
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-36407?
CVE-2020-36407 is a vulnerability in libavif 0.8.0 and 0.8.1 that allows an out-of-bounds write in avifDecoderDataFillImageGrid.
How severe is CVE-2020-36407?
CVE-2020-36407 has a severity score of 8.8 out of 10, indicating a high severity.
What software versions are affected by CVE-2020-36407?
libavif versions 0.8.0 and 0.8.1 are affected by CVE-2020-36407.
How can I fix CVE-2020-36407?
To fix CVE-2020-36407, you should update libavif to version 0.8.2 or later.
Where can I find more information about CVE-2020-36407?
More information about CVE-2020-36407 can be found at the following references: [Reference 1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24811), [Reference 2](https://github.com/AOMediaCodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9), [Reference 3](https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libavif/OSV-2020-1597.yaml).