Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13626

Опубликовано: 17 июл. 2019
Источник: redhat
CVSS3: 6.5

Описание

SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

An out-of-bounds read flaw was discovered in SDL2, in the way that WAVE files are loaded through the SDL_LoadWAV_RW function. An application that uses SDL2 and loads untrusted input files may be vulnerable to this flaw. An attacker can abuse this flaw to crash the application or to leak data from the application's memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5SDLNot affected
Red Hat Enterprise Linux 6SDLNot affected
Red Hat Enterprise Linux 7SDLNot affected
Red Hat Enterprise Linux 8SDLNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1731101SDL: integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c leads to heap-based buffer over-read in Fill_IMA_ADPCM_block

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

CVSS3: 6.5
nvd
больше 6 лет назад

SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

CVSS3: 6.5
debian
больше 6 лет назад

SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buff ...

CVSS3: 6.5
github
больше 3 лет назад

SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость функции IMA_ADPCM_decode() компонента audio/SDL_wave.c мультимедийной библиотеки Simple DirectMedia Layer, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3