PT-2018-1906 · Sdl+2 · Sdl-Image+3

Publicado

2018-03-18

·

Atualizado

2024-04-08

·

CVE-2017-14450

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions sdl-image versions prior to the fixed version SDL2 image version 2.0.2
Description The issue is related to memory handling errors in the image loading library, which can lead to denial of service or execution of arbitrary code. Exploitation of the issue may allow a remote attacker to cause denial of service or compromise data integrity using specially crafted image files. A buffer overflow vulnerability exists in the GIF image parsing functionality, where a specially crafted GIF image can lead to a buffer overflow on a global section.
Recommendations For sdl-image versions prior to the fixed version, update to a version that includes the fix for the memory handling errors. For SDL2 image version 2.0.2, avoid using the GIF image parsing functionality until a patch is available. As a temporary workaround, consider restricting the use of specially crafted image files to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-3678
BDU:2018-01510
CVE-2017-14450
DLA-1341-1
DSA-4177-1
DSA-4184-1
MGASA-2018-0276
MGASA-2018-0454
OPENSUSE-SU-2018_0734-1
OPENSUSE-SU-2024:10608-1
SUSE-SU-2018:3657-1

Produtos afetados

Alt Linux
Sdl2 Image
Suse
Sdl-Image