CVE-2019-13626: Integer Overflow
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in FillIMAADPCMblock, caused by an integer overflow in IMAADPCMdecode() in audio/SDLwave.c.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13626?
CVE-2019-13626 is a vulnerability in SDL (Simple DirectMedia Layer) 2.x through 2.0.9, which allows a heap-based buffer over-read in Fill_IMA_ADPCM_block due to an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
What is the severity of CVE-2019-13626?
The severity of CVE-2019-13626 is medium with a severity value of 6.5.
Which software versions are affected by CVE-2019-13626?
SDL (Simple DirectMedia Layer) versions 2.0.0 through 2.0.9 are affected by CVE-2019-13626.
How can I fix CVE-2019-13626?
To fix CVE-2019-13626, update your SDL (Simple DirectMedia Layer) software to version 2.0.10 or later.
Where can I find more information about CVE-2019-13626?
You can find more information about CVE-2019-13626 at the following references: - [OpenSUSE Security Announcement](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00093.html) - [OpenSUSE Security Announcement](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00094.html) - [Bugzilla](https://bugzilla.libsdl.org/show_bug.cgi?id=4522)