PT-2019-4740 · Simple Directmedia Layer+1 · Sdl2 Image+2

Pwd

·

Published

2019-05-05

·

Updated

2023-02-28

·

CVE-2019-12216

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Simple DirectMedia Layer (SDL) version 2.0.9 SDL2 image version 2.0.4
Description The issue is related to a heap-based buffer overflow in the IMG LoadPCX RW function, located in IMG pcx.c, which can lead to a denial of service. This overflow occurs when the SDL2 image library is used in conjunction with the Simple DirectMedia Layer library.
Recommendations For Simple DirectMedia Layer (SDL) version 2.0.9, consider updating to a newer version to resolve the issue. For SDL2 image version 2.0.4, consider updating to a newer version to resolve the issue. As a temporary workaround, consider restricting the use of the IMG LoadPCX RW function in IMG pcx.c to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2020-01292
CVE-2019-12216
DLA-1861-1
DLA-1865-1
USN-4238-1

Affected Products

Sdl
Sdl2 Image
Ubuntu