In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18776
Reference (s):
- https://bugzilla.libav.org/show_bug.cgi?id=1153