Vulnerability Name:

CVE-2020-36430 (CCN-205939)

Assigned:2020-10-27
Published:2020-10-27
Updated:2022-12-09
Summary:
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-36430

Source: CCN
Type: Google Security Research Issue 26674
libass:libass_fuzzer: Heap-buffer-overflow in decode_chars

Source: cve@mitre.org
Type: Issue Tracking, Patch, Third Party Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
libass-cve202036430-bo(205939)

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: CCN
Type: libass GIT Repository
GitHub - libass/libass: libass is a portable subtitle renderer for the ASS/SSA (Advanced Substation Alpha/Substation Alpha) subtitle format

Source: cve@mitre.org
Type: Patch, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:7920
P
libass-devel-0.14.0-150000.3.11.1 on GA media (Moderate)
2023-06-12
oval:org.opensuse.security:def:6138
P
Security update for java-1_8_0-openjdk (Important)
2022-08-16
oval:org.opensuse.security:def:95356
P
Security update for the Linux Kernel (Important)
2022-07-21
oval:org.opensuse.security:def:3301
P
memcached-1.4.39-4.6.1 on GA media (Moderate)
2022-06-28
oval:org.opensuse.security:def:94931
P
libass-devel-0.14.0-3.9.1 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:94793
P
python3-Jinja2-2.10.1-3.10.2 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:93120
P
(Moderate)
2021-12-23
oval:org.opensuse.security:def:100029
P
(Moderate)
2021-12-07
oval:org.opensuse.security:def:93273
P
(Important)
2021-12-01
oval:org.opensuse.security:def:102069
P
Security update for binutils (Moderate)
2021-11-04
oval:org.opensuse.security:def:101506
P
Security update for ghostscript (Critical)
2021-09-15
oval:org.opensuse.security:def:111018
P
Security update for libass (Important)
2021-08-21
oval:org.opensuse.security:def:65302
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:10136
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:98934
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:92570
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:69711
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:75965
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:9382
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:99719
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:4148
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:91984
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:66897
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:10321
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:101717
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:8638
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:99129
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:111674
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:92769
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:69910
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:76295
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:117686
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:9571
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:4213
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:92179
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:67227
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:74305
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:1026
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:8823
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:99321
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:108172
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:92967
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:70276
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:65237
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:9770
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:5808
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:92371
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:69522
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:74370
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:9018
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:99520
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:108735
P
Security update for libass (Important)
2021-08-20
oval:org.opensuse.security:def:70461
P
Security update for libass (Important)
2021-08-20
BACK