First published: Mon May 20 2019(Updated: )
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_error.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Libsdl Sdl2 Image | =2.0.4 | |
Libsdl Simple Directmedia Layer | =2.0.9 | |
debian/libsdl2-image | 2.0.5+dfsg1-2 2.6.3+dfsg-1 2.8.4+dfsg-1 | |
debian/sdl-image1.2 | 1.2.12-12 1.2.12-13 1.2.12-14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-12219.
The severity of CVE-2019-12219 is high with a CVSS score of 8.8.
The following software is affected by CVE-2019-12219: libsdl2-image 2.0.4, libsdl2 2.0.9, sdl-image1.2 1.2.12.
To fix CVE-2019-12219, update the affected software to the recommended versions: libsdl2-image 2.0.5+dfsg1-2 or later, libsdl2 2.0.9 or later, sdl-image1.2 1.2.12-13 or later.
You can find more information about CVE-2019-12219 at the following references: CVE Details (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12219), Ubuntu Security Notices (https://ubuntu.com/security/notices/USN-4238-1), NIST National Vulnerability Database (https://nvd.nist.gov/vuln/detail/CVE-2019-12219).