PT-2018-1906 · Sdl+2 · Sdl-Image+3

Published

2018-03-18

·

Updated

2024-04-08

·

CVE-2017-14450

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions sdl-image versions prior to the fixed version SDL2 image version 2.0.2
Description The issue is related to memory handling errors in the image loading library, which can lead to denial of service or execution of arbitrary code. Exploitation of the issue may allow a remote attacker to cause denial of service or compromise data integrity using specially crafted image files. A buffer overflow vulnerability exists in the GIF image parsing functionality, where a specially crafted GIF image can lead to a buffer overflow on a global section.
Recommendations For sdl-image versions prior to the fixed version, update to a version that includes the fix for the memory handling errors. For SDL2 image version 2.0.2, avoid using the GIF image parsing functionality until a patch is available. As a temporary workaround, consider restricting the use of specially crafted image files to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-3678
BDU:2018-01510
CVE-2017-14450
DLA-1341-1
DSA-4177-1
DSA-4184-1
MGASA-2018-0276
MGASA-2018-0454
OPENSUSE-SU-2018_0734-1
OPENSUSE-SU-2024:10608-1
SUSE-SU-2018:3657-1

Affected Products

Alt Linux
Sdl2 Image
Suse
Sdl-Image