libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decodechars (called from decodefont and process_text) because the wrong integer data type is used for subtraction.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:0.15.2-1", "binary_name": "libass-dev" }, { "binary_version": "1:0.15.2-1", "binary_name": "libass9" }, { "binary_version": "1:0.15.2-1", "binary_name": "libass9-dbgsym" } ] }