USN-8815-1: libass vulnerabilities
Ubuntu patched libass parsing and outline bugs that can crash the library or possibly run code.
Ubuntu published USN-8815-1 for vulnerabilities in the libass subtitle library. CVE-2020-24994 is a parsing flaw in nested character strings that can crash libass or possibly execute arbitrary code, and it affects Ubuntu 14.04, 16.04, 18.04, and 20.04 LTS. CVE-2020-26682 is an outline-processing bug that can cause a denial of service on Ubuntu 18.04 and 20.04 LTS. The notice also says libass mishandled certain ASS subtitle files.
- CVE-2020-24994 can crash libass or possibly execute code
- Only Ubuntu 14.04, 16.04, 18.04, and 20.04 LTS are affected
- CVE-2020-26682 causes denial of service on 18.04 and 20.04
- The notice does not report active exploitation
Vulnerabilities mentionedAll →
- CVE-2020-249948.83%Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code…published · libass project libass
- CVE-2020-266828.82%In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow
It was discovered that libass incorrectly handled parsing operations for specific nested character strings. An attacker could use this issue to cause libass to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-24994) It was discovered that libass incorrectly handled certain outline processing operations. An attacker could use this issue to cause libass to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-26682) It was discovered that libass incorrectly handled certain ASS subtitle files when…
This source does not provide full text. Read it at ubuntu.com.