First published: Mon May 20 2019(Updated: )
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Libsdl Sdl2 Image | =2.0.4 | |
Libsdl Simple Directmedia Layer | =2.0.9 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =31 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
openSUSE Backports SLE | =15.0 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
Debian Debian Linux | =8.0 | |
debian/libsdl2-image | 2.0.5+dfsg1-2 2.6.3+dfsg-1 2.8.2+dfsg-1 | |
debian/sdl-image1.2 | 1.2.12-12 1.2.12-13 1.2.12-14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12221 is a vulnerability in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used with libSDL2_image.a in SDL2_image 2.0.4.
The severity of CVE-2019-12221 is medium with a CVSS score of 6.5.
CVE-2019-12221 affects libSDL2.a 2.0.9 and libSDL2_image.a 2.0.4.
To fix CVE-2019-12221, you should update to a patched version of libSDL2.a and libSDL2_image.a provided by the software vendors.
You can find more information about CVE-2019-12221 on MITRE's CVE website, Ubuntu Security Notices, and the NIST National Vulnerability Database.