-Infinity
0
Severity
7.1
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L

SDLimage is a library to load images of various formats as SDL surfaces. In dolayersurface() in src/IMGxcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cmnum). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGEINDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.

First published (updated )
Severity
7.5
Buffer Overflow, Input Validation
AV:N/AC:L/Au:N/C:P/I:P/A:P

Buffer overflow in the LWZReadByte function in IMGgif.c in SDLimage before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, a similar issue to CVE-2006-4484. NOTE: some of these details are obtained from third party information.

1 / 2
Source: Red Hat
First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Heap-based buffer overflow in the IMGLoadLBMRW function in IMGlbm.c in SDLimage before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file. NOTE: some of these details are obtained from third party information.

First published (updated )
Severity
6.5
XEE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

First published (updated )
Severity
7

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDLblitN.c when called from SDLSoftBlit in video/SDLblit.c.

Upstream bug:

https://bugzilla.libsdl.org/showbug.cgi?id=4538

First published (updated )
Buffer Overflow

Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device.Security Fix(es): SDL: heap-based buffer overflow in SDL blit functions in video/SDLblit.c (CVE-2019-13616) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

<tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> SDL-1.2.15-33.el8_0.src.rpm </td> <td class="checksum">SHA-256: 09146451e441f2bf11911547a22ab0de2e5744965e828ada0260a92335fc78c8</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> SDL-1.2.15-33.el8_0.ppc64le.rpm </td> <td class="checksum">SHA-256: 98c7466ef7ccaa73b0de798c1e3e56f04468436f9669ec24be04d11727afb440</td> </tr> <tr> <td class="name"> SDL-debuginfo-1.2.15-33.el8_0.ppc64le.rpm </td> <td class="checksum">SHA-256: 18805278ed702fe49132645c4f503cca5efb5923ab65191df9d4f5199c6deb66</td> </tr> <tr> <td class="name"> SDL-debugsource-1.2.15-33.el8_0.ppc64le.rpm </td> <td class="checksum">SHA-256: 20b609f7c58040cb9234fe416b2e2a9498fbfe9a932c5701656392ce1040254f</td> </tr> <tr> <td class="name"> SDL-devel-1.2.15-33.el8_0.ppc64le.rpm </td> <td class="checksum">SHA-256: f892c5190e395795aa5091010e29b82fb91afa11fdb01a57558d317ebb4336ac</td> </tr> </tbody>Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.0 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> SDL-1.2.15-33.el8_0.src.rpm </td> <td class="checksum">SHA-256: 09146451e441f2bf11911547a22ab0de2e5744965e828ada0260a92335fc78c8</td> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> SDL-1.2.15-33.el8_0.i686.rpm </td> <td class="checksum">SHA-256: 23a78912541e0be13de59eb1e4f0af1a743a262f9891bae61e20ed99d74e6526</td> </tr> <tr> <td class="name"> SDL-1.2.15-33.el8_0.x86_64.rpm </td> <td class="checksum">SHA-256: 335dfcf44a4ff4088294c9df4ec42c648ba828cb5b43d18437c3ae3939484379</td> </tr> <tr> <td class="name"> SDL-debuginfo-1.2.15-33.el8_0.i686.rpm </td> <td class="checksum">SHA-256: b7badcb3b6934ee0549e3e6e16a373cdb13e9944a8550e7f772b962d30cb6c28</td> </tr> <tr> <td class="name"> SDL-debuginfo-1.2.15-33.el8_0.x86_64.rpm </td> <td class="checksum">SHA-256: 8418d86db55ff52e1eda26fc3dc7d78f0a2cd4acb7cb011a9226aca7e8699ea1</td> </tr> <tr> <td class="name"> SDL-debugsource-1.2.15-33.el8_0.i686.rpm </td> <td class="checksum">SHA-256: 83c6bc9496bf3cf2a938fa46d1b0234fd0616e3c9fbe45dad868902224d8c10a</td> </tr> <tr> <td class="name"> SDL-debugsource-1.2.15-33.el8_0.x86_64.rpm </td> <td class="checksum">SHA-256: 09887db407fdf96e26bc4c2e56a741208ac763db428127ed1ab843dfb863babe</td> </tr> <tr> <td class="name"> SDL-devel-1.2.15-33.el8_0.i686.rpm </td> <td class="checksum">SHA-256: e49571bc046d813305a571d1b4c844854d3650544985e28760c6ed070145dd4c</td> </tr> <tr> <td class="name"> SDL-devel-1.2.15-33.el8_0.x86_64.rpm </td> <td class="checksum">SHA-256: aeaa878213553546538dece517398a661e160e63b1c34e14bf8b31b3e157b799</td> </tr> </tbody>
First published (updated )

It was discovered that SDLimage incorrectly handled certain image files. An attacker could possibly use this issue to cause a denial of service or other unspecified impact.

First published (updated )
Advisory
USN-4238-1
Buffer Overflow

Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device.Security Fix(es): SDL: heap-based buffer overflow in SDL blit functions in video/SDLblit.c (CVE-2019-13616) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Integer Overflow

It was discovered that SDL 2.0 mishandled crafted image files resulting in an integer overflow. If a user were tricked into opening a malicious file, SDL 2.0 could be caused to crash or potentially run arbitrary code. (CVE-2017-2888) It was discovered that SDL 2.0 mishandled crafted image files. If a user were tricked into opening a malicious file, SDL 2.0 could be caused to crash or potentially run arbitrary code. (CVE-2019-7635, CVE-2019-7636, CVE-2019-7637, CVE-2019-7638)

First published (updated )
Advisory
USN-4143-1

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203