CVE-2020-14410Out-of-bounds Read in Simple Directmedia Layer

CWE-125Out-of-bounds Read8 documents8 sources
Severity
5.4MEDIUMNVD
EPSS
0.2%
top 62.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19
Latest updateMay 24

Description

SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages1 packages

NVDlibsdl/simple_directmedia_layer2.0.122.0.20

Also affects: Debian Linux 9.0, Fedora 33

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vw4m-8vvh-crhf: SDL (Simple DirectMedia Layer) through 22022-05-24
CVEList
CVE-2020-14410: SDL (Simple DirectMedia Layer) through 22021-01-19
OSV
CVE-2020-14410: SDL (Simple DirectMedia Layer) through 22021-01-19

📋Vendor Advisories

3
Ubuntu
Simple DirectMedia Layer vulnerabilities2022-02-07
Red Hat
SDL2: Heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file2021-01-19
Debian
CVE-2020-14410: libsdl1.2 - SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read ...2020

💬Community

1
Bugzilla
CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c2018-02-26
CVE-2020-14410 — Out-of-bounds Read | cvebase