CVE-2020-14409 - log back

CVE-2020-14409 edited at 19 Jan 2021 20:52:40
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
References
+ https://bugzilla.libsdl.org/show_bug.cgi?id=5200
+ https://hg.libsdl.org/SDL/rev/3f9b4e92c1d9
Notes
CVE-2020-14409 created at 19 Jan 2021 20:52:03