Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Grigorig

#18057of 53,625
15Total CVSS
Vulnerabilities · 2
High
2
PT-2017-9436
7.5
2016-10-12
FFmpeg · Libsass · CVE-2016-7970
**Name of the Vulnerable Software and Affected Versions** libass versions prior to 0.13.4 **Description** The issue is related to a buffer overflow in the `calc coeff` function in `libass/ass blur.c`. This allows remote attackers to cause a denial of service via unspecified vectors. **Recommendations** For versions prior to 0.13.4, update to version 0.13.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the `calc coeff` function in `libass/ass blur.c` until a patch is available.
PT-2017-9438
7.5
2016-10-12
None · Libsass · CVE-2016-7972
**Name of the Vulnerable Software and Affected Versions** libass versions prior to 0.13.4 **Description** The issue allows remote attackers to cause a denial of service, specifically a memory allocation failure, via unspecified vectors. This is related to the `check allocations` function in `libass/ass shaper.c`. **Recommendations** For versions prior to 0.13.4, update to version 0.13.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the `check allocations` function in `libass/ass shaper.c` until a patch is available.