In libass 0.14.0, the `ass_outline_construct`’s call to `outline_stroke` causes a signed integer overflow.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26682
Reference (s):
- GENTOO:GLSA-202012-12
- URL: https://security.gentoo.org/glsa/202012-12
- https://github.com/libass/libass/issues/431
- https://github.com/libass/libass/pull/432
- MLIST:[oss-security] 20201119 Re: libass ass_outline.c signed integer overflow