cbcvebase.
CVE-2019-13616
published 2020-01-07

CVE-2019-13616: A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlibsdl1.2< libsdl1.2 1.2.15+dfsg2-5 (bookworm)libsdl1.2 1.2.15+dfsg2-5 (bookworm)
debianlibsdl2< libsdl1.2 1.2.15+dfsg2-5 (bookworm)libsdl1.2 1.2.15+dfsg2-5 (bookworm)
debianlibsdl2-image< libsdl1.2 1.2.15+dfsg2-5 (bookworm)libsdl1.2 1.2.15+dfsg2-5 (bookworm)
debiansdl-image1.2< libsdl1.2 1.2.15+dfsg2-5 (bookworm)libsdl1.2 1.2.15+dfsg2-5 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
libsdlsimple_directmedia_layer<= 1.2.15
libsdlsimple_directmedia_layer2.0.0 – 2.0.9
opensusebackports_sle
opensuseleap
opensuseleap
red_hatsdl
red_hatsdl
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH