Out-of-bounds write in Simple DirectMedia Layer - CVE-2018-3839
Published: April 24, 2018
Vulnerability identifier: #VU12123
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3839
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the XCF image rendering functionality due to out-of-bounds write on the heap. A remote attacker can display a specially crafted XCF image, trick the victim into opening it and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the XCF image rendering functionality due to out-of-bounds write on the heap. A remote attacker can display a specially crafted XCF image, trick the victim into opening it and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Simple DirectMedia Layer
Debian Linux
Gentoo Linux
Fedora
Opensuse
sdl2_image (Alpine package)
SDL2_gfx
SDL2_mixer
SDL2_image
mingw-SDL2_image
SDL2
Debian Linux
Gentoo Linux
Fedora
Opensuse
sdl2_image (Alpine package)
SDL2_gfx
SDL2_mixer
SDL2_image
mingw-SDL2_image
SDL2
How to mitigate CVE-2018-3839
Install update from vendor's website.
sdl2_image (Alpine package) - update to 2.0.1-r2
SDL2_gfx - update to 1.0.3-1.el7
SDL2_mixer - update to 2.0.2-2.el7
SDL2_image - update to 2.0.3-1.el7
mingw-SDL2_image - addressed in versions 2.0.4-1.fc28, 2.0.4-1.fc29
SDL2 - update to 2.0.8-5.el7
SDL2_gfx - update to 1.0.3-1.el7
SDL2_mixer - update to 2.0.2-2.el7
SDL2_image - update to 2.0.3-1.el7
mingw-SDL2_image - addressed in versions 2.0.4-1.fc28, 2.0.4-1.fc29
SDL2 - update to 2.0.8-5.el7
External References
Related Security Bulletins
- Debian update for libsdl2-image
- Debian update for sdl-image1.2
- OpenSUSE Linux update for SDL2
- OpenSUSE Linux update for SDL2
- OpenSUSE Linux update for SDL2
- Gentoo update for SDL2_Image
- Out-of-bounds write in sdl2_image (Alpine package)
- Fedora EPEL 7 update for SDL2, SDL2_gfx, SDL2_image, SDL2_mixer
- Fedora 28 update for mingw-SDL2_image
- Fedora 29 update for mingw-SDL2_image