An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sdl2_image | Oct 1, 2024 | Jul 3, 2019 |
| Debian | — | Upgrade libsdl2-imageUpgrade sdl-image1.2 | Jul 24, 2019 | Jul 3, 2019 |
| Freebsd | — | Upgrade sdl2_image | Jul 3, 2019 | Jul 3, 2019 |
| Suse | — | Upgrade libSDL2_image-devel-64bitUpgrade libSDL2_image-2_0-0-32bitUpgrade libSDL2_image-devel-32bitUpgrade libSDL2_image-2_0-0-64bitUpgrade libSDL2_image-2_0-0Upgrade libSDL2_image-devel | Sep 6, 2019 | Jul 2, 2019 |
| Ubuntu | — | Upgrade libsdl-image1.2 | Jan 15, 2020 | Jul 2, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub