SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit3or4to3or4inversedrgb in video/SDLblitN.c via a crafted .BMP file.
{ "ubuntu_priority": "medium", "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "libsdl2-2.0-0", "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1" }, { "binary_name": "libsdl2-2.0-0-dbgsym", "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1" }, { "binary_name": "libsdl2-dev", "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1" }, { "binary_name": "libsdl2-doc", "binary_version": "2.0.8+dfsg1-1ubuntu1.18.04.4+esm1" } ] }
{ "ubuntu_priority": "medium", "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "libsdl2-2.0-0", "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1" }, { "binary_name": "libsdl2-2.0-0-dbgsym", "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1" }, { "binary_name": "libsdl2-dev", "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1" }, { "binary_name": "libsdl2-doc", "binary_version": "2.0.10+dfsg1-3ubuntu0.1~esm1" } ] }
{ "ubuntu_priority": "medium", "availability": "No subscription required", "binaries": [ { "binary_name": "libsdl2-2.0-0", "binary_version": "2.0.14+dfsg2-3" }, { "binary_name": "libsdl2-2.0-0-dbgsym", "binary_version": "2.0.14+dfsg2-3" }, { "binary_name": "libsdl2-dev", "binary_version": "2.0.14+dfsg2-3" }, { "binary_name": "libsdl2-dev-dbgsym", "binary_version": "2.0.14+dfsg2-3" }, { "binary_name": "libsdl2-doc", "binary_version": "2.0.14+dfsg2-3" } ] }