CVE-2017-14440: High severity sdl_image vulnerability
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2image-2.0.2. A specially crafted ILBM image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-14440?
CVE-2017-14440 is a code execution vulnerability in the ILBM image rendering functionality of SDL2_image-2.0.2.
How does CVE-2017-14440 work?
An attacker can display a specially crafted ILBM image to trigger a stack overflow resulting in code execution.
What is the severity of CVE-2017-14440?
CVE-2017-14440 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2017-14440?
SDL2_image-2.0.2 is affected. For Debian Linux, versions 7.0, 8.0, and 9.0 are affected.
How can I fix CVE-2017-14440?
For SDL2_image-2.0.2, update to version 2.0.4+dfsg1-1+deb10u1, 2.0.5+dfsg1-2, 2.6.3+dfsg-1, or 2.6.3+dfsg-2. For Debian Linux, update to version 1.2.12-10+deb10u1, 1.2.12-12, or 1.2.12-13.