Описание
Security update for libass
This update for libass fixes the following issues:
- CVE-2020-36430: Fixed heap-based buffer overflow in decode_chars (bsc#1188539).
Список пакетов
openSUSE Leap 15.3
libass-devel-0.14.0-3.9.1
libass9-0.14.0-3.9.1
libass9-32bit-0.14.0-3.9.1
Ссылки
- E-Mail link for openSUSE-SU-2021:2792-1
- SUSE Security Ratings
- SUSE Bug 1188539
- SUSE CVE CVE-2020-36430 page
Описание
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
Затронутые продукты
openSUSE Leap 15.3:libass-devel-0.14.0-3.9.1
openSUSE Leap 15.3:libass9-0.14.0-3.9.1
openSUSE Leap 15.3:libass9-32bit-0.14.0-3.9.1
Ссылки
- CVE-2020-36430
- SUSE Bug 1188539