{"id":"CVE-2016-7972","details":"The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.","modified":"2026-05-13T12:00:33.842343777Z","published":"2017-03-03T16:59:00.717Z","related":["SUSE-SU-2016:3107-1","openSUSE-SU-2024:10508-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"23"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"24"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"25"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"42.1"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"13.2"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KW6DNERYHPI5Y6SQYU3XKTVSCOWMIHUC/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7JJ2SGVOX6UQQIRMVC3QACJLKHE2PYN/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUOUOK3VULMMZTNSCRFCNPDAPDWAVK7X/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-12/msg00068.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/93358"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/10/05/2"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1381960"},{"type":"FIX","url":"https://github.com/libass/libass/pull/240/commits/aa54e0b59200a994d50a346b5d7ac818ebcf2d4b"},{"type":"FIX","url":"https://github.com/libass/libass/releases/tag/0.13.4"},{"type":"FIX","url":"https://security.gentoo.org/glsa/201702-25"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libass/libass","events":[{"introduced":"0"},{"last_affected":"27b0232b0d9259bc009389a019eb6b47103f484a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.13.3"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:libass_project:libass:*:*:*:*:*:*:*:*"}}],"versions":["0.13.3","0.13.2","0.13.1","0.13.0","0.12.3","0.12.2","0.12.1","0.12.0","0.11.2","0.11.1","0.11.0","0.10.2","0.10.1","0.10.0","0.9.12","0.9.11","0.9.10","0.9.9","0.9.8","0.9.7"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7972.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}