First published: Wed Jul 17 2019(Updated: )
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libsdl Libsdl | >=2.0.0<=2.0.9 | |
Fedoraproject Fedora | =31 | |
Debian Debian Linux | =10.0 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13626 is a vulnerability in SDL (Simple DirectMedia Layer) 2.x through 2.0.9, which allows a heap-based buffer over-read in Fill_IMA_ADPCM_block due to an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
The severity of CVE-2019-13626 is medium with a severity value of 6.5.
SDL (Simple DirectMedia Layer) versions 2.0.0 through 2.0.9 are affected by CVE-2019-13626.
To fix CVE-2019-13626, update your SDL (Simple DirectMedia Layer) software to version 2.0.10 or later.
You can find more information about CVE-2019-13626 at the following references: - [OpenSUSE Security Announcement](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00093.html) - [OpenSUSE Security Announcement](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00094.html) - [Bugzilla](https://bugzilla.libsdl.org/show_bug.cgi?id=4522)