In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.
{
"binaries": [
{
"binary_version": "1.0.4-1ubuntu3",
"binary_name": "libavif-bin"
},
{
"binary_version": "1.0.4-1ubuntu3",
"binary_name": "libavif-dev"
},
{
"binary_version": "1.0.4-1ubuntu3",
"binary_name": "libavif-gdk-pixbuf"
},
{
"binary_version": "1.0.4-1ubuntu3",
"binary_name": "libavif16"
}
]
}
{
"binaries": [
{
"binary_version": "1.3.0-1ubuntu1",
"binary_name": "libavif-bin"
},
{
"binary_version": "1.3.0-1ubuntu1",
"binary_name": "libavif-dev"
},
{
"binary_version": "1.3.0-1ubuntu1",
"binary_name": "libavif-gdk-pixbuf"
},
{
"binary_version": "1.3.0-1ubuntu1",
"binary_name": "libavif16"
}
]
}