CVE-2016-7972: High severity openSUSE Leap vulnerability
Published Mar 3, 2017
·Updated
The checkallocations function in libass/assshaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
Affected Software
6 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Fedoraproject Fedora=25
Libass Project Libass<=0.13.3
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 3, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7972?
CVE-2016-7972 is classified as a denial of service vulnerability due to memory allocation failure.
2
How do I fix CVE-2016-7972?
To fix CVE-2016-7972, update libass to version 0.13.4 or later.
3
What software is affected by CVE-2016-7972?
CVE-2016-7972 affects libass versions up to 0.13.3 and specific versions of openSUSE and Fedora.
4
What impact does CVE-2016-7972 have on systems?
CVE-2016-7972 can cause applications to crash or become unresponsive, leading to denial of service.
5
Is there a workaround for CVE-2016-7972?
There are no specific workarounds for CVE-2016-7972, the recommended action is to update the software.