CVE-2019-13616

Name
CVE-2019-13616
Description
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://bugzilla.libsdl.org/show_bug.cgi?id=4538
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00014.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00012.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HEH5RO7XZA5DDCO2XOP4QHDEELQQTYV2/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UITVW4WTOOCECLLWPQCV7VWMU66DN255/
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00029.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00030.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00093.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00094.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDNX3RVXTWELBXQDNERNVVKDGKDF2MPB/
Third Party Advisory https://usn.ubuntu.com/4156-1/
Third Party Advisory https://usn.ubuntu.com/4156-2/
Third Party Advisory https://access.redhat.com/errata/RHSA-2019:3951
Third Party Advisory https://access.redhat.com/errata/RHSA-2019:3950
Third Party Advisory https://usn.ubuntu.com/4238-1/
Third Party Advisory https://access.redhat.com/errata/RHSA-2020:0293
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GY6FDFPYUJ7YPY3XB5U75VJHBSVRVIKO/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZO47LLKKRXKMUGSRCFNHSTHG5OEBYCG/
Mailing List https://lists.debian.org/debian-lts-announce/2021/01/msg00024.html
MLIST https://lists.debian.org/debian-lts-announce/2021/10/msg00032.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libsdl:simple_directmedia_layer:*:*:*:*:*:*:*:* simple_directmedia_layer >= None <= 1.2.15
cpe:2.3:a:libsdl:simple_directmedia_layer:*:*:*:*:*:*:*:* simple_directmedia_layer >= 2.0.0 <= 2.0.9

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sdl 3.13-community 1.2.15-r12 Natanael Copa <ncopa@alpinelinux.org> fixed
sdl_image 3.13-community 1.2.12-r5 Natanael Copa <ncopa@alpinelinux.org> fixed
sdl 3.12-main 1.2.15-r12 Natanael Copa <ncopa@alpinelinux.org> fixed
sdl 3.11-main 1.2.15-r12 Natanael Copa <ncopa@alpinelinux.org> fixed
sdl2_image 3.11-main 2.0.5-r1 Francesco Colista <fcolista@alpinelinux.org> fixed
sdl_image 3.11-main 1.2.12-r5 Natanael Copa <ncopa@alpinelinux.org> fixed
sdl 3.10-main 1.2.15-r12 Natanael Copa <ncopa@alpinelinux.org> fixed
sdl_image 3.10-main 1.2.12-r5 Natanael Copa <ncopa@alpinelinux.org> fixed
sdl_image 3.14-community 1.2.12-r5 Natanael Copa <ncopa@alpinelinux.org> fixed