Wind River Support Network

HomeDefectsLIN8-7978
Fixed

LIN8-7978 : Security Advisory - sdl - CVE-2017-2888

Created: Oct 16, 2017    Updated: Apr 9, 2019
Resolved Date: Apr 1, 2019
Found In Version: 8.0.0.22
Fix Version: 8.0.0.30
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

https://nvd.nist.gov/vuln/detail/CVE-2017-2888

CVEs


Live chat
Online