All errata/sisyphus/ALT-PU-2018-3680-1
ALT-PU-2018-3680-1

Package update SDL2_image in branch sisyphus

Version2.0.4-alt1
Published2024-04-08
Max severityHIGH
Severity:

Closed issues (1)

CVE-2018-3977
HIGH8.8

An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

Published: 2018-11-01Modified: 2024-11-21
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS 3.xHIGH 8.8
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H