SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libsdl2 | Feb 10, 2023 | Jul 17, 2019 |
| Gentoo Linux | — | Upgrade media-libs/libsdl2. | Sep 9, 2019 | Jul 17, 2019 |
| Suse | — | Upgrade libsdl2-2_0-0-32bitUpgrade libsdl2-devel-32bitUpgrade libsdl2-2_0-0Upgrade libsdl2-devel | Oct 1, 2019 | Jul 17, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub