| Summary: | a null-pointer-dereference in function stdio_read | ||
|---|---|---|---|
| Product: | SDL_image | Reporter: | pwd <teamseri0us360> |
| Component: | misc | Assignee: | Sam Lantinga <slouken> |
| Status: | RESOLVED FIXED | QA Contact: | Sam Lantinga <slouken> |
| Severity: | normal | ||
| Priority: | P2 | CC: | castro8583bennett, hle, omarandemad |
| Version: | 2.0.4 | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Attachments: | poc | ||
|
Description
pwd
2019-05-09 06:44:04 UTC
This was assigned CVE-2019-12217. I can confirm that this is an issue in SDL_image. The underlying bug is the same as #4628 (CVE-2019-12221). It is also fixed by the same patch ([PATCH] pcx: do not write directly to row buffer). Please see https://bugzilla.libsdl.org/show_bug.cgi?id=4628 This is fixed, thanks! Thank you! Fix Castro B, http://sitederencontrebelge.be |