Out-of-bounds Write Affecting simple_directmedia_layer package, versions [,1.2.15.post1)[2.0.0,2.0.10)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.07% (77th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SIMPLEDIRECTMEDIALAYER-2379497
  • published26 Jan 2022
  • disclosed7 Jan 2020
  • creditUnknown

Introduced: 7 Jan 2020

CVE-2019-14906  (opens in a new tab)
CWE-787  (opens in a new tab)

How to fix?

Upgrade simple_directmedia_layer to version 1.2.15.post1, 2.0.10 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Write. A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.

CVSS Base Scores

version 3.1