CVE-2022-27470: High severity sdl_ttf vulnerability
Published May 4, 2022
·Updated
SDLttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTFRenderTextSolid(). This vulnerability is triggered via a crafted TTF file.
Affected Software
4 affected components
libSDL Sdl Ttf<=2.0.18
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Remediation
Patch Available
Event History
May 4, 2022
CVE Published
via MITRE·02:34 AM
Data Sourced
via MITRE·02:34 AM
Description
Frequently Asked Questions
1
What is CVE-2022-27470?
CVE-2022-27470 refers to a vulnerability in SDL_ttf v2.0.18 and below that allows for arbitrary memory write via the function TTF_RenderText_Solid().
2
How can the CVE-2022-27470 vulnerability be triggered?
The CVE-2022-27470 vulnerability is triggered through a crafted TTF file.
3
What is the severity of CVE-2022-27470?
CVE-2022-27470 has a severity rating of 7.8 out of 10 (high severity).
4
Which software versions are affected by CVE-2022-27470?
SDL_ttf v2.0.18 and below, Libsdl Sdl Ttf, Fedora 34, Fedora 35, and Fedora 36.
5
How can I fix CVE-2022-27470?
To fix CVE-2022-27470, it is recommended to update to a version of SDL_ttf that is above v2.0.18.