PT-2019-12707 · Simple Directmedia Layer+2 · Sdl2 Image+3

Published

2019-05-20

·

Updated

2022-03-30

·

CVE-2019-12221

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Simple DirectMedia Layer (SDL) version 2.0.9 SDL2 image version 2.0.4
Description An issue was discovered in libSDL2.a when used with libSDL2 image.a. There is a segmentation fault in the SDL function at stdlib/SDL malloc.c.
Recommendations For Simple DirectMedia Layer (SDL) version 2.0.9, update to a version that fixes the issue in the SDL free REAL function. For SDL2 image version 2.0.4, update to a version that fixes the issue when used in conjunction with Simple DirectMedia Layer (SDL) 2.0.9. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12221
DLA-1861-1
DLA-1865-1
MGASA-2019-0363
MGASA-2019-0364
OPENSUSE-SU-2019:2070-1
OPENSUSE-SU-2019:2108-1
OPENSUSE-SU-2019_2070-1
OPENSUSE-SU-2024:10608-1
USN-4238-1

Affected Products

Sdl
Sdl2 Image
Suse
Ubuntu