PT-2019-12704 · Simple Directmedia Layer+2 · Sdl2 Image+3

Published

2019-05-20

·

Updated

2020-01-14

·

CVE-2019-12218

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Simple DirectMedia Layer (SDL) version 2.0.9 SDL2 image version 2.0.4
Description An issue was discovered in libSDL2.a when used with libSDL2 image.a. There is a NULL pointer dereference in the IMG LoadPCX RW function at IMG pcx.c.
Recommendations For Simple DirectMedia Layer (SDL) version 2.0.9, consider updating to a newer version to resolve the issue. For SDL2 image version 2.0.4, consider updating to a newer version to resolve the issue. As a temporary workaround, consider restricting the use of the IMG LoadPCX RW function until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12218
DLA-1861-1
DLA-1865-1
MGASA-2019-0363
MGASA-2019-0364
OPENSUSE-SU-2019:2070-1
OPENSUSE-SU-2019:2108-1
OPENSUSE-SU-2019_2070-1
OPENSUSE-SU-2024:10608-1
USN-4238-1

Affected Products

Sdl
Sdl2 Image
Suse
Ubuntu