An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.4+dfsg1-2ubuntu2.16.04.2", "binary_name": "libsdl2-2.0-0" }, { "binary_version": "2.0.4+dfsg1-2ubuntu2.16.04.2", "binary_name": "libsdl2-2.0-0-dbgsym" }, { "binary_version": "2.0.4+dfsg1-2ubuntu2.16.04.2", "binary_name": "libsdl2-dbg" }, { "binary_version": "2.0.4+dfsg1-2ubuntu2.16.04.2", "binary_name": "libsdl2-dev" }, { "binary_version": "2.0.4+dfsg1-2ubuntu2.16.04.2", "binary_name": "libsdl2-dev-dbgsym" }, { "binary_version": "2.0.4+dfsg1-2ubuntu2.16.04.2", "binary_name": "libsdl2-doc" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.1", "binary_name": "libsdl2-2.0-0" }, { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.1", "binary_name": "libsdl2-2.0-0-dbgsym" }, { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.1", "binary_name": "libsdl2-dev" }, { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.1", "binary_name": "libsdl2-doc" } ] }