SB2016122014 - Out-of-bounds read in libass (Alpine package)
Published: December 20, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2016-7969)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=c1846533a801fb147bb1798d7ffc7c2c6390435c
- https://git.alpinelinux.org/aports/commit/?id=6a2c2c382bf2a4d22808faa5102be32a8f3e20a6
- https://git.alpinelinux.org/aports/commit/?id=24e6168f3854d0a1595fe1d0d9b45f9398f563b9
- https://git.alpinelinux.org/aports/commit/?id=2688f5da763997e1600d4c3d1b7ea0246f6b539a
- https://git.alpinelinux.org/aports/commit/?id=5817f9550cd9518445687dba125fbb3554618c67