SB2016122015 - Buffer overflow in libass (Alpine package)
Published: December 20, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2016-7970)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=c1846533a801fb147bb1798d7ffc7c2c6390435c
- https://git.alpinelinux.org/aports/commit/?id=24e6168f3854d0a1595fe1d0d9b45f9398f563b9
- https://git.alpinelinux.org/aports/commit/?id=2688f5da763997e1600d4c3d1b7ea0246f6b539a
- https://git.alpinelinux.org/aports/commit/?id=5817f9550cd9518445687dba125fbb3554618c67