Wind River Support Network

HomeDefectsLIN10-2216
Fixed

LIN10-2216 : Security Advisory - sdl - CVE-2017-2888

Created: Oct 16, 2017    Updated: Mar 27, 2019
Resolved Date: Mar 12, 2019
Found In Version: 10.17.41.1
Fix Version: 10.17.41.15
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

https://nvd.nist.gov/vuln/detail/CVE-2017-2888

CVEs


Live chat
Online