First published: Tue Apr 10 2018(Updated: )
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libsdl2-image | 2.0.4+dfsg1-1+deb10u1 2.0.5+dfsg1-2 2.6.3+dfsg-1 2.6.3+dfsg-2 | |
debian/sdl-image1.2 | 1.2.12-10+deb10u1 1.2.12-12 1.2.12-13 | |
Libsdl Sdl Image | =2.0.2 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3838 is an exploitable information vulnerability in the XCF image rendering functionality of Simple DirectMedia Layer (SDL2_image-2.0.2).
The severity of CVE-2018-3838 is medium.
Libsdl Sdl Image versions 2.0.2 are affected, as well as certain versions of libsdl2-image and sdl-image1.2 packages on Debian Linux 8.0 and 9.0.
An attacker can exploit CVE-2018-3838 by displaying a specially crafted XCF image, which can cause an out-of-bounds read on the heap, resulting in information disclosure.
To fix CVE-2018-3838, update the affected packages to the recommended versions provided by Debian Linux and SDL.