Your submission was sent successfully! Close

CVE-2019-7573

Published: 07 February 2019

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).

From the Ubuntu security team

It was discovered that SDL (Simple DirectMedia Layer) did not properly handle certain crafted input, resulting in a heap-based buffer over-read. An attacker could use this to cause SDL to crash or leak sensitive information.

Priority

Low

CVSS 3 base score: 8.8

Status

Package Release Status
libsdl1.2
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(1.2.15+dfsg2-5)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(1.2.15+dfsg2-5)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(1.2.15+dfsg2-5)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1.2.15+dfsg2-0.1ubuntu0.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (1.2.15+dfsg1-3ubuntu0.1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (1.2.15-8ubuntu1.1+esm1)
Patches:
Upstream: https://hg.libsdl.org/SDL/rev/fcbecae42795
libsdl2
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.10 (Impish Indri) Not vulnerable
(2.0.10+dfsg1-1ubuntu1)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(2.0.10+dfsg1-1ubuntu1)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(2.0.10+dfsg1-1ubuntu1)
Ubuntu 18.04 LTS (Bionic Beaver) Needed

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needed)
Ubuntu 14.04 ESM (Trusty Tahr) Needed

Patches:
Upstream: https://hg.libsdl.org/SDL/rev/f9a9d6c76b21