CVE-2018-3838: Medium severity sdl_image vulnerability
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3838?
CVE-2018-3838 is an exploitable information vulnerability in the XCF image rendering functionality of Simple DirectMedia Layer (SDL2_image-2.0.2).
What is the severity of CVE-2018-3838?
The severity of CVE-2018-3838 is medium.
What software versions are affected by CVE-2018-3838?
Libsdl Sdl Image versions 2.0.2 are affected, as well as certain versions of libsdl2-image and sdl-image1.2 packages on Debian Linux 8.0 and 9.0.
How can an attacker exploit CVE-2018-3838?
An attacker can exploit CVE-2018-3838 by displaying a specially crafted XCF image, which can cause an out-of-bounds read on the heap, resulting in information disclosure.
How can I fix CVE-2018-3838?
To fix CVE-2018-3838, update the affected packages to the recommended versions provided by Debian Linux and SDL.