CVE-2018-3837
published 2018-04-10CVE-2018-3837: An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
1.25%
66.0th percentile
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco_systems_inc | simple_direct_media | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libsdl2-image | < libsdl2-image 2.0.3+dfsg1-1 (bookworm) | libsdl2-image 2.0.3+dfsg1-1 (bookworm) |
| debian | sdl-image1.2 | < libsdl2-image 2.0.3+dfsg1-1 (bookworm) | libsdl2-image 2.0.3+dfsg1-1 (bookworm) |
| freedesktop | poppler | >= 0 < 0.24.5-2ubuntu4.14 | 0.24.5-2ubuntu4.14 |
| freedesktop | poppler | >= 0 < 0.41.0-0ubuntu1.10 | 0.41.0-0ubuntu1.10 |
| freedesktop | poppler | >= 0 < 0.62.0-2ubuntu2.5 | 0.62.0-2ubuntu2.5 |
| libsdl | sdl_image | — | — |
| starwindsoftware | starwind_virtual_san | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gwvh-mf23-368g: An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2
ghsa_unreviewed·2022-05-13
CVE-2018-3837 [MEDIUM] CWE-125 GHSA-gwvh-mf23-368g: An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
OSV
poppler regression
osv·2018-12-11·CVSS 6.5
CVE-2018-16646 poppler regression
poppler regression
USN-3837-1 fixed vulnerabilities in poppler. A regression was reported
regarding the previous update. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that poppler incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-16646)
It was discovered that poppler incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-19149)
OSV
CVE-2018-3837: An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2
osv·2018-04-10·CVSS 5.5
CVE-2018-3837 [MEDIUM] CVE-2018-3837: An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
Debian
CVE-2018-3837: libsdl2-image - An exploitable information disclosure vulnerability exists in the PCX image rend...
vendor_debian·2018·CVSS 5.5
CVE-2018-3837 [MEDIUM] CVE-2018-3837: libsdl2-image - An exploitable information disclosure vulnerability exists in the PCX image rend...
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-1)
bullseye: resolved (fixed in 2.0.3+dfsg1-1)
forky: resolved (fixed in 2.0.3+dfsg1-1)
sid: resolved (fixed in 2.0.3+dfsg1-1)
trixie: resolved (fixed in 2.0.3+dfsg1-1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple Simple DirectMedia Layer Vulnerabilities
blogs_talos·2018-04-11·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Multiple Simple DirectMedia Layer Vulnerabilities
## Vulnerability Spotlight: Multiple Simple DirectMedia Layer Vulnerabilities
Discovered by Lilith Wyatt of Cisco Talos
## Overview
Talos is disclosing several vulnerabilities identified in Simple DirectMedia Layer's SDL2_Image library that could allow code execution. Simple DirectMedia Layer is a cross-platform development library designed to provide low level access to audio, keyboard, mouse, joystick, and graphics hardware via OpenGL and Direct3D. It is used by video playback software, emulators, and popular games including Valve's award winning catalog and many Humble Bundle games. SDL officially supports Windows, Mac OS X, Linux, iOS, and Android. Support for other platforms may be found in the source code. The SDL2_Image library is an optional component for SDL that deals specific
Talos
Vulnerability Spotlight: Multiple Simple DirectMedia Layer Vulnerabilities
blogs_talos·2018-04-11·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Multiple Simple DirectMedia Layer Vulnerabilities
Discovered by Lilith Wyatt of Cisco Talos
### Overview
Talos is disclosing several vulnerabilities identified in Simple DirectMedia Layer's SDL2_Image library that could allow code execution. Simple DirectMedia Layer is a cross-platform development library designed to provide low level access to audio, keyboard, mouse, joystick, and graphics hardware via OpenGL and Direct3D. It is used by video playback software, emulators, and popular games including Valve's award winning catalog and many Humble Bundle games. SDL officially supports Windows, Mac OS X, Linux, iOS, and Android. Support for other platforms may be found in the source code. The SDL2_Image library is an optional component for SDL that deals specifically with parsing and displaying a variety of image file formats, creating a s
Bugzilla
CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 mingw-SDL2_image: various flaws [fedora-all]
bugzilla·2018-04-16·CVSS 5.5
CVE-2018-3837 [MEDIUM] CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 mingw-SDL2_image: various flaws [fedora-all]
CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 mingw-SDL2_image: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 SDL2_image: various flaws [epel-7]
bugzilla·2018-04-16·CVSS 5.5
CVE-2018-3837 [MEDIUM] CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 SDL2_image: various flaws [epel-7]
CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 SDL2_image: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpk
Bugzilla
CVE-2018-3837 SDL2_image: information disclosure in the PCX image rendering functionality
bugzilla·2018-04-16·CVSS 5.5
CVE-2018-3837 [MEDIUM] CVE-2018-3837 SDL2_image: information disclosure in the PCX image rendering functionality
CVE-2018-3837 SDL2_image: information disclosure in the PCX image rendering functionality
A flaw was found in SDL2_image-2.0.2. An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0519
Discussion:
Created SDL2_image tracking bugs for this issue:
Affects: fedora-all [bug 1568146]
Created mingw-SDL2_image tracking bugs for this issue:
Affects: fedora-all [bug 1568144]
Created SDL2_image tracking bugs for this issue:
Affects: epel-7 [bug
Bugzilla
CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 SDL2_image: various flaws [fedora-all]
bugzilla·2018-04-16·CVSS 5.5
CVE-2018-3837 [MEDIUM] CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 SDL2_image: various flaws [fedora-all]
CVE-2018-3837 CVE-2018-3838 CVE-2018-3839 SDL2_image: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
https://security.gentoo.org/glsa/201903-17https://www.debian.org/security/2018/dsa-4177https://www.debian.org/security/2018/dsa-4184https://www.starwindsoftware.com/security/sw-20191008-0001/https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0519https://security.gentoo.org/glsa/201903-17https://www.debian.org/security/2018/dsa-4177https://www.debian.org/security/2018/dsa-4184https://www.starwindsoftware.com/security/sw-20191008-0001/https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0519
2018-04-10
Published