Updated libass packages fix security vulnerability
Publication date: 27 Aug 2021Modification date: 27 Aug 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2020-36430
Description
Updated libass packages fix security vulnerability: libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction (CVE-2020-36430).
References
SRPMS
8/core
- libass-0.15.1-1.mga8