CVE-2019-12220
Published: 20 May 2019
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an out-of-bounds read in the SDL function SDL_FreePalette_REAL at video/SDL_pixels.c.
From the Ubuntu security team
USN-4238-1 addressed serveral vulnerabilities in SDL_image. This update provides the corresponding fixes for Ubuntu 14.04 ESM.
Priority
CVSS 3 base score: 6.5
Status
Package | Release | Status |
---|---|---|
libsdl2-image Launchpad, Ubuntu, Debian |
bionic |
Needed
|
disco |
Ignored
(reached end-of-life)
|
|
eoan |
Not vulnerable
(2.0.5+dfsg1-1)
|
|
focal |
Not vulnerable
(2.0.5+dfsg1-1)
|
|
groovy |
Not vulnerable
(2.0.5+dfsg1-1)
|
|
hirsute |
Not vulnerable
(2.0.5+dfsg1-1)
|
|
impish |
Not vulnerable
(2.0.5+dfsg1-1)
|
|
jammy |
Not vulnerable
(2.0.5+dfsg1-1)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(2.0.5+dfsg1-1)
|
|
xenial |
Ignored
(end of standard support, was needed)
|
|
sdl-image1.2 Launchpad, Ubuntu, Debian |
bionic |
Released
(1.2.12-8ubuntu0.1)
|
disco |
Ignored
(reached end-of-life)
|
|
eoan |
Not vulnerable
(1.2.12-11)
|
|
focal |
Not vulnerable
(1.2.12-11)
|
|
groovy |
Not vulnerable
(1.2.12-11)
|
|
hirsute |
Not vulnerable
(1.2.12-11)
|
|
impish |
Not vulnerable
(1.2.12-11)
|
|
jammy |
Not vulnerable
(1.2.12-11)
|
|
precise |
Does not exist
|
|
trusty |
Needed
|
|
upstream |
Released
(1.2.12-11)
|
|
xenial |
Released
(1.2.12-5+deb9u1ubuntu0.16.04.1)
|
Notes
Author | Note |
---|---|
mdeslaur | same fix as CVE-2019-12222 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12220
- https://ubuntu.com/security/notices/USN-4238-1
- NVD
- Launchpad
- Debian