CVE-2020-26682: Integer Overflow
Published Oct 16, 2020
·Updated
In libass 0.14.0, the assoutlineconstruct's call to outlinestroke causes a signed integer overflow.
Affected Software
2 affected componentsFixes available
Libass Project Libass=0.14.0
debian/libass
1:0.17.1-11:0.17.1-1+deb12u11:0.17.3-1+deb13u11:0.17.5-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libassto a version that resolves this vulnerability.Fixed in 1:0.17.1-1Fixed in 1:0.17.1-1+deb12u1Fixed in 1:0.17.3-1+deb13u1Fixed in 1:0.17.5-1
Event History
Oct 16, 2020
CVE Published
via MITRE·01:19 PM
Data Sourced
via MITRE·01:19 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 24, 2026
Data Sourced
via Launchpad·07:11 PM
Description
Data Sourced
via Debian·07:11 PM
DescriptionAffected Software
Sep 25, 2026
Data Sourced
via Ubuntu·07:11 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-26682?
CVE-2020-26682 is a vulnerability found in libass 0.14.0 that causes a signed integer overflow when the ass_outline_construct function calls outline_stroke.
2
How severe is CVE-2020-26682?
CVE-2020-26682 has a severity rating of 8.8, which is considered high.
3
Which software version is affected by CVE-2020-26682?
CVE-2020-26682 affects version 0.14.0 of the Libass Project's libass.
4
How can CVE-2020-26682 be fixed?
To fix CVE-2020-26682, users should update libass to a version that contains the patch for the vulnerability.
5
Where can I find more information about CVE-2020-26682?
More information about CVE-2020-26682 can be found in the references: [link1], [link2], [link3].