sdl2

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description A library for portable low-level access to a video framebuffer, audio output, mouse, and keyboard (Version 2)
Version 2.0.18-1 [extra]

Resolved

Group Affected Fixed Severity Status Ticket
AVG-1480 2.0.12-3 2.0.14-1 Medium Fixed
AVG-891 2.0.9-1 2.0.10-1 High Fixed
Issue Group Severity Remote Type Description
CVE-2020-14410 AVG-1480 Low No Denial of service
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
CVE-2020-14409 AVG-1480 Medium No Arbitrary code execution
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c...
CVE-2019-7638 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
CVE-2019-7636 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
CVE-2019-7635 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
CVE-2019-7578 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
CVE-2019-7577 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
CVE-2019-7576 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the...
CVE-2019-7575 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
CVE-2019-7574 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
CVE-2019-7573 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).
CVE-2019-7572 AVG-891 High Yes Arbitrary code execution
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.

Advisories

Date Advisory Group Severity Type
05 Aug 2019 ASA-201908-5 AVG-891 High arbitrary code execution