PT-2020-9627 · Sdl+3 · Sdl+3

Riccardo Schirone

·

Published

2019-08-29

·

Updated

2023-02-12

·

CVE-2019-14906

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SDL versions prior to 1.2.15 SDL versions 2.x prior to 2.0.9
Description A heap-based buffer overflow flaw exists while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image. This issue affects applications that use SDL to parse untrusted input files, which could allow an attacker to make the application crash or execute code.
Recommendations For SDL versions prior to 1.2.15, update to a version later than 1.2.15 to resolve the issue. For SDL versions 2.x prior to 2.0.9, update to a version later than 2.0.9 to resolve the issue. As a temporary workaround, consider restricting the use of SDL for parsing untrusted input files until a patch is available.

Fix

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2572
ALT-PU-2019-3262
CESA-2019_4024
CVE-2019-14906
RHSA-2019:4024
RHSA-2019_4024

Affected Products

Alt Linux
Centos
Red Hat
Sdl