PT-2019-4740 · Simple Directmedia Layer+1 · Sdl2 Image+2
Pwd
·
Publicado
2019-05-05
·
Atualizado
2023-02-28
·
CVE-2019-12216
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Simple DirectMedia Layer (SDL) version 2.0.9
SDL2 image version 2.0.4
Description
The issue is related to a heap-based buffer overflow in the
IMG LoadPCX RW function, located in IMG pcx.c, which can lead to a denial of service. This overflow occurs when the SDL2 image library is used in conjunction with the Simple DirectMedia Layer library.Recommendations
For Simple DirectMedia Layer (SDL) version 2.0.9, consider updating to a newer version to resolve the issue.
For SDL2 image version 2.0.4, consider updating to a newer version to resolve the issue.
As a temporary workaround, consider restricting the use of the
IMG LoadPCX RW function in IMG pcx.c to minimize the risk of exploitation.Exploit
Correção
Memory Corruption
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sdl
Sdl2 Image
Ubuntu