CVE-2020-26682: Integer Overflow
Published Oct 16, 2020
·Updated
In libass 0.14.0, the assoutlineconstruct's call to outlinestroke causes a signed integer overflow.
Affected Software
1 affected component
Libass Project Libass=0.14.0
Event History
Oct 16, 2020
CVE Published
via MITRE·01:19 PM
Data Sourced
via MITRE·01:19 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26682?
CVE-2020-26682 is a vulnerability found in libass 0.14.0 that causes a signed integer overflow when the ass_outline_construct function calls outline_stroke.
2
How severe is CVE-2020-26682?
CVE-2020-26682 has a severity rating of 8.8, which is considered high.
3
Which software version is affected by CVE-2020-26682?
CVE-2020-26682 affects version 0.14.0 of the Libass Project's libass.
4
How can CVE-2020-26682 be fixed?
To fix CVE-2020-26682, users should update libass to a version that contains the patch for the vulnerability.
5
Where can I find more information about CVE-2020-26682?
More information about CVE-2020-26682 can be found in the references: [link1], [link2], [link3].