CVE-2019-12220: Medium severity libSDL Sdl2 Image vulnerability
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2image.a in SDL2image 2.0.4. There is an out-of-bounds read in the SDL function SDLFreePaletteREAL at video/SDLpixels.c.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12220?
CVE-2019-12220 is a vulnerability in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used with libSDL2_image.a in SDL2_image 2.0.4, which allows for an out-of-bounds read in the SDL function SDL_FreePalette_REAL at video/SDL_pixels.c.
What is the severity of CVE-2019-12220?
The severity of CVE-2019-12220 is medium, with a severity value of 6.5.
What software is affected by CVE-2019-12220?
The software affected by CVE-2019-12220 is libsdl:sdl2_image 2.0.4 and libsdl:simple_directmedia_layer 2.0.9.
How can I fix CVE-2019-12220 in libsdl2-image?
To fix CVE-2019-12220 in libsdl2-image, update to versions 2.0.4+dfsg1-1+deb10u1, 2.0.5+dfsg1-2, 2.6.3+dfsg-1, or 2.6.3+dfsg-2.
How can I fix CVE-2019-12220 in sdl-image1.2?
To fix CVE-2019-12220 in sdl-image1.2, update to versions 1.2.12-10+deb10u1, 1.2.12-12, or 1.2.12-13.