An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-3839.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "v8-build12533"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "v8-build12658"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "v8-build12859"
}
]
}
]