There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.
{ "binaries": [ { "binary_name": "libsdl1.2-dbg", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2-dev", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2-dev-dbgsym", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2debian", "binary_version": "1.2.15-8ubuntu1.1+esm2" }, { "binary_name": "libsdl1.2debian-dbgsym", "binary_version": "1.2.15-8ubuntu1.1+esm2" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_name": "libsdl1.2-dev", "binary_version": "1.2.15+dfsg1-3ubuntu0.1+esm1" }, { "binary_name": "libsdl1.2debian", "binary_version": "1.2.15+dfsg1-3ubuntu0.1+esm1" }, { "binary_name": "libsdl1.2debian-dbgsym", "binary_version": "1.2.15+dfsg1-3ubuntu0.1+esm1" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_name": "libsdl1.2-dev", "binary_version": "1.2.15+dfsg2-0.1ubuntu0.2" }, { "binary_name": "libsdl1.2debian", "binary_version": "1.2.15+dfsg2-0.1ubuntu0.2" }, { "binary_name": "libsdl1.2debian-dbgsym", "binary_version": "1.2.15+dfsg2-0.1ubuntu0.2" } ], "availability": "No subscription required" }