CVE-2020-36430: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
Affected products
- Fedoraproject Fedora: version 34 only
- Libass Project Libass: from 0.15.0, before 0.15.1 (fixed in 0.15.1)
Published 2021-07-20. Last modified 2026-06-17.