PT-2017-15596 · Sdl+1 · Sdl Image+1
Published
2017-10-11
·
Updated
2024-04-08
·
CVE-2017-2887
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SDL image version 2.0.1
Description
A buffer overflow vulnerability exists in the XCF property handling functionality. A specially crafted XCF file can cause a stack-based buffer overflow, potentially leading to code execution. An attacker can trigger this issue by providing a specially crafted XCF file.
Recommendations
For SDL image version 2.0.1, update to a version that fixes this issue to prevent potential code execution. As a temporary workaround, consider restricting the handling of XCF files until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Sdl Image