6.8
CVSSv2

CVE-2021-33657

Published: 01/04/2022 Updated: 03/05/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libsdl simple directmedia layer

Vendor Advisories

Debian Bug report logs - #1014577 libsdl12: CVE-2021-33657 Package: src:libsdl12; Maintainer for src:libsdl12 is Debian SDL packages maintainers <pkg-sdl-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 8 Jul 2022 07:21:04 UTC Severity: important Tags: security ...
There is a heap overflow problem in video/SDL_pixelsc in SDL (Simple DirectMedia Layer) 2x to 2018 versions By crafting a malicious BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution ...