In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18778
Reference (s):
- https://bugzilla.libav.org/show_bug.cgi?id=1155

