track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
{ "binaries": [ { "binary_name": "ffmpeg", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "ffmpeg-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "ffmpeg-doc", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavcodec-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavcodec-extra", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavcodec-extra58", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavcodec-extra58-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavcodec58", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavcodec58-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavdevice-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavdevice58", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavdevice58-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavfilter-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavfilter-extra", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavfilter-extra7", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavfilter-extra7-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavfilter7", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavfilter7-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavformat-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavformat58", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavformat58-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavresample-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavresample4", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavresample4-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavutil-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavutil56", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libavutil56-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libpostproc-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libpostproc55", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libpostproc55-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libswresample-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libswresample3", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libswresample3-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libswscale-dev", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libswscale5", "binary_version": "7:4.2.7-0ubuntu0.1" }, { "binary_name": "libswscale5-dbgsym", "binary_version": "7:4.2.7-0ubuntu0.1" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }