Wind River Support Network

HomeDefectsLIN9-5554
Fixed

LIN9-5554 : Security Advisory - sdl - CVE-2017-2888

Created: Oct 16, 2017    Updated: May 18, 2019
Resolved Date: Apr 19, 2019
Found In Version: 9.0.0.11
Fix Version: 9.0.0.21
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

https://nvd.nist.gov/vuln/detail/CVE-2017-2888

CVEs


Live chat
Online