Bug#975108: libass9: Signed integer overflow (undefined behavior)
Package: libass9
Version: 1:0.14.0-2
Severity: normal
Dear Maintainer,
please see upstream issue:
https://github.com/libass/libass/issues/431
This is fixed in version 0.15.* (and thus in Debian testing and unstable)
but I feel it still bears reporting because of possible security implications.
-- System Information:
Debian Release: 10.6
APT prefers stable
APT policy: (990, 'stable'), (500, 'stable-updates'), (500, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 4.19.0-12-amd64 (SMP w/4 CPU cores)
Kernel taint flags: TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: sysvinit (via /sbin/init)
Versions of packages libass9 depends on:
ii libc6 2.28-10
ii libfontconfig1 2.13.1-2
ii libfreetype6 2.9.1-3+deb10u2
ii libfribidi0 1.0.5-3.1+deb10u1
ii libharfbuzz0b 2.3.1-1
libass9 recommends no packages.
libass9 suggests no packages.
-- no debconf information
Reply to: