CVE-2019-12217: Null Pointer Dereference
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2image.a in SDL2image 2.0.4. There is a NULL pointer dereference in the SDL stdioread function in file/SDLrwops.c.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12217?
CVE-2019-12217 is a vulnerability in Simple DirectMedia Layer (SDL) 2.0.9 and SDL2_image 2.0.4 that allows for a NULL pointer dereference in the SDL stdio_read function.
What is the severity of CVE-2019-12217?
The severity of CVE-2019-12217 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2019-12217?
CVE-2019-12217 affects libSDL2.a in SDL 2.0.9 and libSDL2_image.a in SDL2_image 2.0.4.
How can I fix CVE-2019-12217?
To fix CVE-2019-12217, update to a version of SDL and SDL2_image that includes the necessary fix.
Where can I find more information about CVE-2019-12217?
More information about CVE-2019-12217 can be found at the following references: [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12217), [Ubuntu Security Notices](https://ubuntu.com/security/notices/USN-4238-1), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-12217)