SB2016122016 - Resource management error in libass (Alpine package)
Published: December 20, 2016
Security Bulletin ID
SB2016122016
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2016-7972)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=c1846533a801fb147bb1798d7ffc7c2c6390435c
- https://git.alpinelinux.org/aports/commit/?id=f96df33aed05055667c4b2455c14a31f95d62394
- https://git.alpinelinux.org/aports/commit/?id=6a2c2c382bf2a4d22808faa5102be32a8f3e20a6
- https://git.alpinelinux.org/aports/commit/?id=24e6168f3854d0a1595fe1d0d9b45f9398f563b9
- https://git.alpinelinux.org/aports/commit/?id=2688f5da763997e1600d4c3d1b7ea0246f6b539a
- https://git.alpinelinux.org/aports/commit/?id=5817f9550cd9518445687dba125fbb3554618c67