In libass 0.14.0, the ass_outline_construct's call to outline_stroke causes a signed integer overflow.
References
- http://www.openwall.com/lists/oss-security/2020/11/19/7
- http://www.openwall.com/lists/oss-security/2020/11/19/7
- https://github.com/libass/libass/issues/431
- https://github.com/libass/libass/issues/431
- https://github.com/libass/libass/pull/432
- https://github.com/libass/libass/pull/432
- https://security.gentoo.org/glsa/202012-12
- https://security.gentoo.org/glsa/202012-12