CVE-2019-5058: High severity sdl2_image vulnerability
Published Jul 31, 2019
·Updated
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Affected Software
5 affected components
libSDL Sdl2 Image=2.0.4
openSUSE Backports SLE=15.0
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.0
openSUSE Leap=15.1
Event History
Jul 31, 2019
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-5058.
2
What is the severity of CVE-2019-5058?
The severity of CVE-2019-5058 is high.
3
Which software versions are affected by CVE-2019-5058?
SDL2_image 2.0.4, openSUSE Backports SLE 15.0, openSUSE Backports SLE 15.0-sp1, openSUSE Leap 15.0, and openSUSE Leap 15.1 are affected by CVE-2019-5058.
4
How can an attacker exploit CVE-2019-5058?
An attacker can exploit CVE-2019-5058 by displaying a specially crafted XCF image.
5
Is there a fix available for CVE-2019-5058?
Yes, there are patches available to fix CVE-2019-5058. Please refer to the references for more information.