SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit3or4to3or4inversedrgb in video/SDLblitN.c via a crafted .BMP file.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1", "binary_name": "libsdl2-2.0-0" }, { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1", "binary_name": "libsdl2-2.0-0-dbgsym" }, { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1", "binary_name": "libsdl2-dev" }, { "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1", "binary_name": "libsdl2-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1", "binary_name": "libsdl2-2.0-0" }, { "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1", "binary_name": "libsdl2-2.0-0-dbgsym" }, { "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1", "binary_name": "libsdl2-dev" }, { "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1", "binary_name": "libsdl2-doc" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.14+dfsg2-3", "binary_name": "libsdl2-2.0-0" }, { "binary_version": "2.0.14+dfsg2-3", "binary_name": "libsdl2-2.0-0-dbgsym" }, { "binary_version": "2.0.14+dfsg2-3", "binary_name": "libsdl2-dev" }, { "binary_version": "2.0.14+dfsg2-3", "binary_name": "libsdl2-dev-dbgsym" }, { "binary_version": "2.0.14+dfsg2-3", "binary_name": "libsdl2-doc" } ] }