CVE-2017-12122: High severity libSDL Sdl Image vulnerability
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2image-2.0.2. A specially crafted ILBM image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12122?
The severity of CVE-2017-12122 is high with a score of 8.8.
How does the code execution vulnerability in CVE-2017-12122 work?
The code execution vulnerability in CVE-2017-12122 is triggered by a specially crafted ILBM image that causes a heap overflow, leading to code execution.
Which software versions are affected by CVE-2017-12122?
The affected software versions for CVE-2017-12122 include libsdl2-image 2.0.2, sdl-image1.2 1.2.12, and various Debian Linux versions.
How can I fix CVE-2017-12122?
To fix CVE-2017-12122, update to the recommended versions of libsdl2-image or sdl-image1.2 depending on your system, as provided in the vulnerability description.
Where can I find more information about CVE-2017-12122?
More information about CVE-2017-12122 can be found in the references provided: https://lists.debian.org/debian-lts-announce/2018/04/msg00005.html, https://security.gentoo.org/glsa/201903-17, and https://www.debian.org/security/2018/dsa-4177.