First published: Wed May 04 2022(Updated: )
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SDL_ttf | <=2.0.18 | |
Fedora | =34 | |
Fedora | =35 | |
Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27470 refers to a vulnerability in SDL_ttf v2.0.18 and below that allows for arbitrary memory write via the function TTF_RenderText_Solid().
The CVE-2022-27470 vulnerability is triggered through a crafted TTF file.
CVE-2022-27470 has a severity rating of 7.8 out of 10 (high severity).
SDL_ttf v2.0.18 and below, Libsdl Sdl Ttf, Fedora 34, Fedora 35, and Fedora 36.
To fix CVE-2022-27470, it is recommended to update to a version of SDL_ttf that is above v2.0.18.