Heap-based buffer overflow in libass - CVE-2020-36430
Published: August 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in decode_chars (called from decode_font and process_text). A remote attacker can pass specially crafted data to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
openEuler
Fedora
libass-debugsource
libass-devel
libass9
libass9-debuginfo
libass
libass-debuginfo
libass-help
media-libs/libass
How to mitigate CVE-2020-36430
libass-debugsource - update to 0.14.0-3.9.1
libass-devel - update to 0.14.0-3.9.1
libass9 - update to 0.14.0-3.9.1
libass9-debuginfo - update to 0.14.0-3.9.1
libass - update to 0.15.0-2
libass-debuginfo - update to 0.15.0-2
libass-debugsource - update to 0.15.0-2
libass-devel - update to 0.15.0-2
libass-help - update to 0.15.0-2
media-libs/libass - update to 0.15.1
libass - update to 0.15.2-1.fc34