First published: Thu Jul 28 2022(Updated: )
SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libsdl Simple Directmedia Layer | >=1.2.1<=1.2.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34568 is a vulnerability discovered in SDL v1.2 that allows for a use-after-free via the XFree function.
CVE-2022-34568 has a severity rating of 7.5 (high).
CVE-2022-34568 affects the affected software by allowing an attacker to exploit a use-after-free vulnerability in the SDL library, potentially leading to arbitrary code execution or a denial of service.
To fix CVE-2022-34568, it is recommended to update the affected software to a version that includes the necessary patch or upgrade to a version of SDL that is no longer vulnerable.
More information about CVE-2022-34568 can be found in the official SDL GitHub repository (https://github.com/libsdl-org/SDL-1.2/issues/863) and the Gentoo Security Advisory (https://security.gentoo.org/glsa/202305-17).