An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "v8-build12533"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "v8-build12658"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "v8-build12859"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-3837.json"