CVE-2020-36430

HIGH

Libass < 0.15.1 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.

References (5)

Core 5

Scores

CVSS v3 7.8
EPSS 0.0031
EPSS Percentile 54.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (2)
fedoraproject/fedora 34
libass_project/libass 0.15.0 - 0.15.1
Published Jul 20, 2021
Tracked Since Feb 18, 2026