Related Vulnerabilities: CVE-2020-26682  

In libass 0.14.0, the ass_outline_construct's call to outline_stroke causes a signed integer overflow.

Severity Medium

Remote No

Type Arbitrary code execution

Description

In libass 0.14.0, the ass_outline_construct's call to outline_stroke causes a signed integer overflow.

AVG-1285 libass 0.14.0-2 0.15.0-1 Medium Fixed

https://github.com/libass/libass/issues/431
https://github.com/libass/libass/pull/432
https://github.com/libass/libass/commit/676f9dc5b52ef406c5527bdadbcb947f11392929