| Summary: | an out-of-bounds read in function SDL_FreePalette_REAL at SDL_pixels.c:731-9 | ||
|---|---|---|---|
| Product: | SDL_image | Reporter: | pwd <teamseri0us360> |
| Component: | misc | Assignee: | Sam Lantinga <slouken> |
| Status: | RESOLVED FIXED | QA Contact: | Sam Lantinga <slouken> |
| Severity: | normal | ||
| Priority: | P2 | CC: | hle |
| Version: | 2.0.4 | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Attachments: | poc | ||
|
Description
pwd
2019-05-09 06:46:23 UTC
This issue was assigned CVE-2019-12220. I confirm that the bug is located in SDL_image. This issue is very similar to #4621 (CVE-2019-12222) and is fixed by the same patch ([PATCH] pcx: cast size and check calloc return value). This is fixed, thanks! |