There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.
{ "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libsdl1.2-dbg", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2-dev", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2-dev-dbgsym", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2debian", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2debian-dbgsym", "binary_version": "1.2.15-8ubuntu1.1+esm2" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libsdl1.2-dev", "binary_version": "1.2.15+dfsg1-3ubuntu0.1+esm1" }, { "binary_name": "libsdl1.2debian", "binary_version": "1.2.15+dfsg1-3ubuntu0.1+esm1" }, { "binary_name": "libsdl1.2debian-dbgsym", "binary_version": "1.2.15+dfsg1-3ubuntu0.1+esm1" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libsdl1.2-dev", "binary_version": "1.2.15+dfsg2-0.1ubuntu0.2" }, { "binary_name": "libsdl1.2debian", "binary_version": "1.2.15+dfsg2-0.1ubuntu0.2" }, { "binary_name": "libsdl1.2debian-dbgsym", "binary_version": "1.2.15+dfsg2-0.1ubuntu0.2" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libsdl2-2.0-0", "binary_version": "2.0.20+dfsg-2" }, { "binary_name": "libsdl2-2.0-0-dbgsym", "binary_version": "2.0.20+dfsg-2" }, { "binary_name": "libsdl2-dev", "binary_version": "2.0.20+dfsg-2" }, { "binary_name": "libsdl2-dev-dbgsym", "binary_version": "2.0.20+dfsg-2" }, { "binary_name": "libsdl2-doc", "binary_version": "2.0.20+dfsg-2" } ], "availability": "No subscription required" }