CVE-2019-13626
published 2019-07-17CVE-2019-13626: SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode()…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.80%
76.2th percentile
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libsdl1.2 | < libsdl2 2.0.10+dfsg1-1 (bookworm) | libsdl2 2.0.10+dfsg1-1 (bookworm) |
| debian | libsdl2 | < libsdl2 2.0.10+dfsg1-1 (bookworm) | libsdl2 2.0.10+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libsdl | libsdl | 2.0.0 – 2.0.9 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block
vendor_redhat·2019-07-17·CVSS 6.5
CVE-2019-13626 [MEDIUM] CWE-190 SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block
SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
An out-of-bounds read flaw was discovered in SDL2, in the way that WAVE files are loaded through the SDL_LoadWAV_RW function. An application that uses SDL2 and loads untrusted input files may be vulnerable to this flaw. An attacker can abuse this flaw to crash the application or to leak data from the application's memory.
Package: SDL (Red Hat Enterprise Linux 5) - Not affected
Package: SDL (Red Hat Enterprise Linux 6) - Not affected
Package: SDL (Red Hat Enterprise Linux 7) - Not aff
Debian
CVE-2019-13626: libsdl1.2 - SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-re...
vendor_debian·2019·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626: libsdl1.2 - SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-re...
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
Scope: local
bookworm: resolved
bullseye: resolved
GHSA
GHSA-cfw8-jr6q-wg89: SDL (Simple DirectMedia Layer) 2
ghsa_unreviewed·2022-05-24
CVE-2019-13626 [MEDIUM] CWE-125 GHSA-cfw8-jr6q-wg89: SDL (Simple DirectMedia Layer) 2
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
OSV
CVE-2019-13626: SDL (Simple DirectMedia Layer) 2
osv·2019-07-17·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626: SDL (Simple DirectMedia Layer) 2
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13626 mingw-SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [epel-all]
bugzilla·2019-09-23·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626 mingw-SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [epel-all]
CVE-2019-13626 mingw-SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
Bugzilla
CVE-2019-13626 mingw-SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
bugzilla·2019-09-23·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626 mingw-SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
CVE-2019-13626 mingw-SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changel
Bugzilla
CVE-2019-13626 SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
bugzilla·2019-09-23·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626 SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
CVE-2019-13626 SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2019-13626 SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [epel-all]
bugzilla·2019-09-23·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626 SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [epel-all]
CVE-2019-13626 SDL2: SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2019-13626 SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block
bugzilla·2019-07-18·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626 SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block
CVE-2019-13626 SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4522
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1731103]
---
(In reply to Dhananjay Arunesh from comment #1)
> Created SDL tracking bugs for this issue:
>
> Affects: fedora-all [bug 1731103]
Didn't you mistaken SDL with SDL2? SDL is not vulnerable because does not support 24-bit WAVE format.
---
Upstream fix:
https://hg.libsdl.org/SDL/rev/b06fa7da012b
---
Created SDL2 track
Bugzilla
CVE-2019-13626 SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
bugzilla·2019-07-18·CVSS 6.5
CVE-2019-13626 [MEDIUM] CVE-2019-13626 SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
CVE-2019-13626 SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00093.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00094.htmlhttps://bugzilla.libsdl.org/show_bug.cgi?id=4522https://lists.debian.org/debian-lts-announce/2023/02/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6FDFPYUJ7YPY3XB5U75VJHBSVRVIKO/https://security.gentoo.org/glsa/201909-07http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00093.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00094.htmlhttps://bugzilla.libsdl.org/show_bug.cgi?id=4522https://lists.debian.org/debian-lts-announce/2023/02/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6FDFPYUJ7YPY3XB5U75VJHBSVRVIKO/https://security.gentoo.org/glsa/201909-07
2019-07-17
Published