Rapid7

vulnerability

Debian: CVE-2019-12220: libsdl2-image, sdl-image1.2 -- security update

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
May 20, 2019
Added
Jul 24, 2019
Modified
Mar 30, 2026

Description

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an out-of-bounds read in the SDL function SDL_FreePalette_REAL at video/SDL_pixels.c.

Solutions

debian-upgrade-libsdl2-imagedebian-upgrade-sdl-image1-2
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.