Описание
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 2.0.3+dfsg1-1 |
| devel | not-affected | 2.0.3+dfsg1-1 |
| esm-apps/bionic | not-affected | 2.0.3+dfsg1-1 |
| esm-apps/xenial | released | 2.0.1+dfsg-2+deb9u1build0.16.04.1 |
| esm-infra-legacy/trusty | released | 2.0.0+dfsg-3+deb8u1build0.14.04.1 |
| precise/esm | DNE | |
| trusty | released | 2.0.0+dfsg-3+deb8u1build0.14.04.1 |
| trusty/esm | released | 2.0.0+dfsg-3+deb8u1build0.14.04.1 |
| upstream | released | 2.0.3+dfsg1-1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 1.2.12-8 |
| devel | not-affected | 1.2.12-8 |
| esm-apps/bionic | not-affected | 1.2.12-8 |
| esm-apps/xenial | released | 1.2.12-5+deb9u1build0.16.04.1 |
| esm-infra-legacy/trusty | released | 1.2.12-5+deb9u1build0.14.04.1 |
| precise/esm | DNE | |
| trusty | released | 1.2.12-5+deb9u1build0.14.04.1 |
| trusty/esm | released | 1.2.12-5+deb9u1build0.14.04.1 |
| upstream | released | 1.2.12-8 |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.
An exploitable information vulnerability exists in the XCF image rende ...
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3