5.8
CVSSv2

CVE-2019-7635

Published: 08/02/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

SDL (Simple DirectMedia Layer) up to and including 1.2.15 and 2.x up to and including 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libsdl simple directmedia layer

opensuse leap 42.3

opensuse leap 15.0

opensuse leap 15.1

opensuse backports sle 15.0

debian debian linux 8.0

debian debian linux 9.0

fedoraproject fedora 31

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

Vendor Advisories

Synopsis Moderate: SDL security update Type/Severity Security Advisory: Moderate Topic An update for SDL is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which give ...
Debian Bug report logs - #924609 libsdl12: Multiple security issues Package: src:libsdl12; Maintainer for src:libsdl12 is Debian SDL packages maintainers <pkg-sdl-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 14 Mar 2019 21:36:02 UTC Severity: grave Tags: patch, ...
Debian Bug report logs - #932754 libsdl2-image: multiple security issues Package: src:libsdl2-image; Maintainer for src:libsdl2-image is Debian SDL packages maintainers <pkg-sdl-maintainers@listsaliothdebianorg>; Reported by: Hugo Lefeuvre <hle@debianorg> Date: Mon, 22 Jul 2019 18:45:01 UTC Severity: important Ta ...
Several security issues were fixed in SDL ...
SDL 20 could be made to crash or run programs as your login if it opened a specially crafted file ...
Several security issues were fixed in SDL ...
Several security issues were fixed in SDL_image ...
SDL (Simple DirectMedia Layer) through 1215 and 2x through 209 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wavec (CVE-2019-7572) SDL (Simple DirectMedia Layer) through 1215 and 2x through 209 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wavec (inside the wNumCoef loop) (CVE-2019-7573) SDL (Simple DirectMe ...
Impact: Moderate Public Date: 2019-02-07 CWE: CWE-122 Bugzilla: 1677158: CVE-2019-7635 SDL: heap-based ...
SDL (Simple DirectMedia Layer) through 1215 and 2x through 209 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1c ...

References

CWE-125https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720https://bugzilla.libsdl.org/show_bug.cgi?id=4498https://lists.debian.org/debian-lts-announce/2019/03/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00088.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00014.htmlhttps://security.gentoo.org/glsa/201909-07http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00030.htmlhttps://usn.ubuntu.com/4143-1/https://usn.ubuntu.com/4156-1/https://usn.ubuntu.com/4156-2/https://lists.debian.org/debian-lts-announce/2019/10/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2019/10/msg00021.htmlhttps://usn.ubuntu.com/4238-1/https://lists.debian.org/debian-lts-announce/2021/01/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2021/10/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2023/02/msg00008.htmlhttps://security.gentoo.org/glsa/202305-17https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ZO47LLKKRXKMUGSRCFNHSTHG5OEBYCG/https://access.redhat.com/errata/RHSA-2020:4627https://nvd.nist.govhttps://usn.ubuntu.com/4156-2/