CVE-2020-14410: Medium severity sdl-1.2 vulnerability
Published Jan 19, 2021
·Updated
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit3or4to3or4inversedrgb in video/SDLblitN.c via a crafted .BMP file.
Affected Software
4 affected components
libSDL Simple DirectMedia Layer>=2.0.12<=2.0.20
Debian Debian Linux=9.0
Fedoraproject Fedora=33
libSDL Simple DirectMedia Layer<=2.0.12
Remediation
Patch Available
Event History
Jan 19, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this SDL (Simple DirectMedia Layer) vulnerability?
The vulnerability ID of this SDL vulnerability is CVE-2020-14410.
2
What is the severity rating of CVE-2020-14410?
CVE-2020-14410 has a severity rating of medium with a score of 5.4.
3
Which software versions are affected by this vulnerability?
Versions up to and including 2.0.12 of Libsdl Simple Directmedia Layer, Debian Linux 9.0, and Fedora 33 are affected by this vulnerability.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by using a crafted .BMP file.
5
Is there a fix available for CVE-2020-14410?
Yes, there have been fixes released. Please refer to the provided references for more information.