Stack-based buffer overflow in Simple DirectMedia Layer - CVE-2017-2887
Published: October 10, 2017 / Updated: October 11, 2017
Vulnerability details
The vulnerability exists in the XCF property handling function of Simple DirectMedia Layer SDL_image due to stack-based buffer overflow. A remote attacker can send a specially crafted xcf file, trick the victim into opening it, trigger memory corruption and execute arbitrary code with privileges of the current user.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Fedora
sdl2_image (Alpine package)
SDL2_gfx
SDL2_image
SDL2_mixer
mingw-SDL2_image
mingw-SDL2_mixer
SDL2
mingw-SDL2
How to mitigate CVE-2017-2887
SDL2_gfx - update to 1.0.3-1.el7
SDL2_image - addressed in versions 2.0.1-8.fc25, 2.0.1-8.fc26, 2.0.1-8.fc27, 2.0.3-1.el7, 2.0.4-1.el7, 2.0.4-1.fc28, 2.0.4-1.fc29
SDL2_mixer - update to 2.0.2-2.el7
mingw-SDL2_image - addressed in versions 2.0.4-1.el7, 2.0.4-1.fc28, 2.0.4-1.fc29
mingw-SDL2_mixer - update to 2.0.4-1.el7
SDL2 - update to 2.0.8-5.el7
mingw-SDL2 - update to 2.0.9-1.el7
External References
Related Security Bulletins
- Remote code execution in Simple DirectMedia Layer
- Debian update for libsdl2-image
- Debian update for sdl-image1.2
- Stack-based buffer overflow in sdl2_image (Alpine package)
- Fedora 27 update for SDL2_image
- Fedora 26 update for SDL2_image
- Fedora 25 update for SDL2_image
- Fedora EPEL 7 update for SDL2, SDL2_gfx, SDL2_image, SDL2_mixer
- Fedora 28 update for SDL2_image
- Fedora 29 update for SDL2_image
- Fedora EPEL 7 update for SDL2_image
- Fedora 28 update for mingw-SDL2_image
- Fedora 29 update for mingw-SDL2_image
- Fedora EPEL 7 update for mingw-SDL2, mingw-SDL2_image, mingw-SDL2_mixer