PT-2019-12706 · Simple Directmedia Layer+2 · Sdl2 Image+3

Hugo Lefeuvre

·

Publicado

2019-05-20

·

Atualizado

2020-01-14

·

CVE-2019-12220

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Simple DirectMedia Layer (SDL) version 2.0.9 SDL2 image version 2.0.4
Description An issue was discovered in libSDL2.a when used with libSDL2 image.a. There is an out-of-bounds read in the SDL FreePalette REAL function at video/SDL pixels.c.
Recommendations For Simple DirectMedia Layer (SDL) version 2.0.9, consider updating to a newer version to resolve the issue. For SDL2 image version 2.0.4, consider updating to a newer version to resolve the issue. As a temporary workaround, consider restricting the use of the SDL FreePalette REAL function until a patch is available.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12220
DLA-1861-1
DLA-1865-1
MGASA-2019-0363
MGASA-2019-0364
OPENSUSE-SU-2019:2070-1
OPENSUSE-SU-2019:2108-1
OPENSUSE-SU-2019_2070-1
OPENSUSE-SU-2024:10608-1
USN-4238-1

Produtos afetados

Sdl
Sdl2 Image
Suse
Ubuntu