First published: Tue Jan 19 2021(Updated: )
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsdl Simple DirectMedia Layer | >=2.0.12<=2.0.20 | |
Fedora | =33 | |
Debian | =9.0 | |
StarWind Virtual SAN | =v8-build12533 | |
StarWind Virtual SAN | =v8-build12658 | |
StarWind Virtual SAN | =v8-build12859 | |
StarWind Virtual SAN | =v8-build13170 | |
StarWind Virtual SAN | =v8-build13586 | |
StarWind Virtual SAN | =v8-build13861 | |
libsdl Simple DirectMedia Layer | <=2.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14409 is an Integer Overflow vulnerability in SDL (Simple DirectMedia Layer) through version 2.0.12, which can result in heap corruption.
CVE-2020-14409 affects SDL versions up to and including 2.0.12, potentially leading to heap corruption when processing a crafted .BMP file.
The following software products are affected: Libsdl Simple Directmedia Layer, Fedoraproject Fedora 33, Debian Debian Linux 9.0, Starwindsoftware Starwind Virtual San (versions v8-build12533, v8-build12658, v8-build12859, v8-build13170, v8-build13586, v8-build13861).
CVE-2020-14409 has a severity rating of 7.8 (High).
To fix CVE-2020-14409, update to a version of SDL that is not affected by the vulnerability (2.0.13 or later).