Debian Libsdl2 vulnerabilities
18 known vulnerabilities affecting debian/libsdl2.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH15LOW3
Vulnerabilities
Page 1 of 1
CVE-2022-4743HIGHCVSS 7.5fixed in libsdl2 2.26.0+dfsg-1 (bookworm)2022
CVE-2022-4743 [HIGH] CVE-2022-4743: libsdl2 - A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() fun...
A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.
Scope: local
bookworm: resolved (fixed in 2.26.0+dfsg-1)
bullseye: resolved (fixed in 2.0.14+dfsg2-3+deb11u2)
for
debian
CVE-2021-33657HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-7 (bookworm)2021
CVE-2021-33657 [HIGH] CVE-2021-33657: libsdl1.2 - There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedi...
There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-7)
bullseye: open
debian
CVE-2020-14409HIGHCVSS 7.8fixed in libsdl2 2.0.14+dfsg2-2 (bookworm)2020
CVE-2020-14409 [HIGH] CVE-2020-14409: libsdl2 - SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resul...
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
Scope: local
bookworm: resolved (fixed in 2.0.14+dfsg2-2)
bullseye: resolved (fixed in 2.0.14+dfsg2-2)
forky: resolved (fixed in 2.0.14+dfsg2-2)
sid: resolved (fixed in 2.0.14+dfsg2-2)
trix
debian
CVE-2020-14410LOWCVSS 5.4fixed in libsdl2 2.0.14+dfsg2-2 (bookworm)2020
CVE-2020-14410 [MEDIUM] CVE-2020-14410: libsdl1.2 - SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read ...
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
Scope: local
bookworm: resolved
bullseye: resolved
debian
CVE-2019-7635HIGHCVSS 8.1fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7635 [HIGH] CVE-2019-7635: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7576HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7576 [HIGH] CVE-2019-7576: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7638HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7638 [HIGH] CVE-2019-7638: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7575HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7575 [HIGH] CVE-2019-7575: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7637HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7637 [HIGH] CVE-2019-7637: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7636HIGHCVSS 8.1fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7636 [HIGH] CVE-2019-7636: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7577HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7577 [HIGH] CVE-2019-7577: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7573HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7573 [HIGH] CVE-2019-7573: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7572HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7572 [HIGH] CVE-2019-7572: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-13616HIGHCVSS 8.1fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-13616 [HIGH] CVE-2019-13616: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7574HIGHCVSS 8.8fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7574 [HIGH] CVE-2019-7574: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-7578HIGHCVSS 8.1fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7578 [HIGH] CVE-2019-7578: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-13626LOWCVSS 6.5fixed in libsdl2 2.0.10+dfsg1-1 (bookworm)2019
CVE-2019-13626 [MEDIUM] CVE-2019-13626: libsdl1.2 - SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-re...
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
Scope: local
bookworm: resolved
bullseye: resolved
debian
CVE-2017-2888LOWCVSS 8.8fixed in libsdl2 2.0.6+dfsg1-4 (bookworm)2017
CVE-2017-2888 [HIGH] CVE-2017-2888: libsdl1.2 - An exploitable integer overflow vulnerability exists when creating a new RGB Sur...
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
Scope: local
bo
debian