Bugzilla – Bug 1188539
VUL-0: CVE-2020-36430: libass: heap-based buffer overflow in decode_chars
Last modified: 2024-05-13 16:21:20 UTC
CVE-2020-36430 libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-36430 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26674 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36430 https://github.com/libass/libass/commit/017137471d0043e0321e377ed8da48e45a3ec632 https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libass/OSV-2020-2099.yaml http://www.cvedetails.com/cve/CVE-2020-36430/
I consider: 15/libass: affected 12/libass: not affected, expression does not contain subtraction at all
Tumbleweed: already fixed by version update
Package submitted: 15/libass I believe all fixed.
# maintenance_jira_update_notice openSUSE-SU-2021:2792-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1188539 CVE References: CVE-2020-36430 JIRA References: Sources used: openSUSE Leap 15.3 (src): libass-0.14.0-3.9.1
# maintenance_jira_update_notice SUSE-SU-2021:2792-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1188539 CVE References: CVE-2020-36430 JIRA References: Sources used: SUSE Manager Server 4.0 (src): libass-0.14.0-3.9.1 SUSE Manager Retail Branch Server 4.0 (src): libass-0.14.0-3.9.1 SUSE Manager Proxy 4.0 (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise Server for SAP 15 (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise Server 15-LTSS (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): libass-0.14.0-3.9.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): libass-0.14.0-3.9.1 SUSE Enterprise Storage 6 (src): libass-0.14.0-3.9.1 SUSE CaaS Platform 4.0 (src): libass-0.14.0-3.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
# maintenance_jira_update_notice openSUSE-SU-2021:1174-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1188539 CVE References: CVE-2020-36430 JIRA References: Sources used: openSUSE Leap 15.2 (src): libass-0.14.0-lp152.4.9.1