vulnerability

Oracle Linux: CVE-2019-13616: ELSA-2019-3951: SDL security update (IMPORTANT) (Multiple Advisories)

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:P)
Published
Jul 30, 2019
Added
Oct 5, 2022
Modified
Dec 3, 2025

Description

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
A heap-based buffer overflow was discovered in SDL in the SDL_BlitCopy() function, that was called while copying an existing surface into a new optimized one, due to lack of validation while loading a BMP image in the SDL_LoadBMP_RW() function. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or possibly execute code.

Solutions

oracle-linux-upgrade-sdloracle-linux-upgrade-sdl-develoracle-linux-upgrade-sdl-static
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.