Out-of-bounds write in Simple DirectMedia Layer - CVE-2018-3839

 

Out-of-bounds write in Simple DirectMedia Layer - CVE-2018-3839

Published: April 24, 2018


Vulnerability identifier: #VU12123
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3839
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the XCF image rendering functionality due to out-of-bounds write on the heap. A remote attacker can display a specially crafted XCF image, trick the victim into opening it and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Simple DirectMedia Layer
Debian Linux
Gentoo Linux
Fedora
Opensuse
sdl2_image (Alpine package)
SDL2_gfx
SDL2_mixer
SDL2_image
mingw-SDL2_image
SDL2

How to mitigate CVE-2018-3839

Install update from vendor's website.

sdl2_image (Alpine package) - update to 2.0.1-r2
SDL2_gfx - update to 1.0.3-1.el7
SDL2_mixer - update to 2.0.2-2.el7
SDL2_image - update to 2.0.3-1.el7
mingw-SDL2_image - addressed in versions 2.0.4-1.fc28, 2.0.4-1.fc29
SDL2 - update to 2.0.8-5.el7

External References

Related Security Bulletins