Описание
Security update for libass
This update for libass fixes the following issues:
CVE-2016-7969, CVE-2016-7970, CVE-2016-7971, CVE-2016-7972: Fixed multiple memory allocation issues found by fuzzing (bsc#1002982).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP1
SUSE Linux Enterprise Software Development Kit 12 SP2
Ссылки
- Link for SUSE-SU-2016:3107-1
- E-Mail link for SUSE-SU-2016:3107-1
- SUSE Security Ratings
- SUSE Bug 1002982
- SUSE CVE CVE-2016-7969 page
- SUSE CVE CVE-2016-7970 page
- SUSE CVE CVE-2016-7971 page
- SUSE CVE CVE-2016-7972 page
Описание
The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
Затронутые продукты
Ссылки
- CVE-2016-7969
- SUSE Bug 1002982
Описание
Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.
Затронутые продукты
Ссылки
- CVE-2016-7970
- SUSE Bug 1002982
Описание
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Затронутые продукты
Ссылки
- CVE-2016-7971
- SUSE Bug 1002982
Описание
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
Затронутые продукты
Ссылки
- CVE-2016-7972
- SUSE Bug 1002982