CVE-2019-5051: Buffer Overflow
Published Jul 3, 2019
·Updated
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
Affected Software
10 affected componentsFixes available
libSDL Sdl2 Image=2.0.4
Debian Debian Linux=8.0
openSUSE Backports SLE=15.0
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.0
openSUSE Leap=15.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
debian/libsdl2-image
2.0.5+dfsg1-22.6.3+dfsg-12.8.8+dfsg-12.8.8+dfsg-2
debian/sdl-image1.2
1.2.12-121.2.12-131.2.12-14
Event History
Jul 3, 2019
CVE Published
via MITRE·06:43 PM
Data Sourced
via MITRE·06:43 PM
DescriptionSeverityWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:29 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·11:10 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·11:11 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-5051?
CVE-2019-5051 is an exploitable heap-based buffer overflow vulnerability that exists when loading a PCX file in SDL2_image, version 2.0.4.
2
How can an attacker exploit CVE-2019-5051?
An attacker can exploit CVE-2019-5051 by providing a specially crafted PCX image file to trigger the buffer overflow and potentially execute code.
3
What is the severity of CVE-2019-5051?
CVE-2019-5051 has a severity rating of 8.8 (high).
4
Which software versions are affected by CVE-2019-5051?
SDL2_image version 2.0.4 is affected by CVE-2019-5051.
5
How do I fix CVE-2019-5051?
To fix CVE-2019-5051, upgrade to SDL2_image version 2.0.5+dfsg1-1 or higher.