CVE-2019-7635

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.

References

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00063.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00073.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00088.html

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00014.html

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00030.html

https://bugzilla.libsdl.org/show_bug.cgi?id=4498

https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720

https://lists.debian.org/debian-lts-announce/2019/03/msg00015.html

https://lists.debian.org/debian-lts-announce/2019/03/msg00016.html

https://lists.debian.org/debian-lts-announce/2019/07/msg00021.html

https://lists.debian.org/debian-lts-announce/2019/07/msg00026.html

https://lists.debian.org/debian-lts-announce/2019/10/msg00020.html

https://lists.debian.org/debian-lts-announce/2019/10/msg00021.html

https://lists.debian.org/debian-lts-announce/2021/01/msg00024.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/7ZO47LLKKRXKMUGSRCFNHSTHG5OEBYCG/

https://security.gentoo.org/glsa/201909-07

https://usn.ubuntu.com/4143-1/

https://usn.ubuntu.com/4156-1/

https://usn.ubuntu.com/4156-2/

https://usn.ubuntu.com/4238-1/

Details

Source: MITRE

Published: 2019-02-08

Updated: 2021-02-23

Type: CWE-125

Risk Information

CVSS v2

Base Score: 5.8

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Impact Score: 4.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Impact Score: 5.2

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (34 total)

IDNameProductFamilySeverity
147263NewStart CGSL MAIN 6.02 : SDL Multiple Vulnerabilities (NS-SA-2021-0077)NessusNewStart CGSL Local Security Checks
high
147259NewStart CGSL CORE 5.04 / MAIN 5.04 : SDL Multiple Vulnerabilities (NS-SA-2021-0042)NessusNewStart CGSL Local Security Checks
high
146035CentOS 8 : SDL (CESA-2020:4627)NessusCentOS Local Security Checks
high
145772Debian DLA-2536-1 : libsdl2 security updateNessusDebian Local Security Checks
high
143077RHEL 7 : SDL (RHSA-2020:3868)NessusRed Hat Local Security Checks
high
142805Oracle Linux 8 : SDL (ELSA-2020-4627)NessusOracle Linux Local Security Checks
high
142387RHEL 8 : SDL (RHSA-2020:4627)NessusRed Hat Local Security Checks
high
141985Amazon Linux 2 : SDL (ALAS-2020-1500)NessusAmazon Linux Local Security Checks
high
141691Scientific Linux Security Update : SDL on SL7.x x86_64 (20201001)NessusScientific Linux Local Security Checks
high
141585CentOS 7 : SDL (CESA-2020:3868)NessusCentOS Local Security Checks
high
141228Oracle Linux 7 : SDL (ELSA-2020-3868)NessusOracle Linux Local Security Checks
high
133882Fedora 31 : mingw-SDL (2020-24652fe41c)NessusFedora Local Security Checks
high
132933Ubuntu 16.04 LTS / 18.04 LTS : SDL_image vulnerabilities (USN-4238-1)NessusUbuntu Local Security Checks
high
129968Ubuntu 16.04 LTS / 18.04 LTS : SDL vulnerabilities (USN-4156-1)NessusUbuntu Local Security Checks
high
129489Ubuntu 16.04 LTS / 18.04 LTS / 19.04 : SDL 2.0 vulnerabilities (USN-4143-1)NessusUbuntu Local Security Checks
high
128596GLSA-201909-07 : Simple DirectMedia Layer: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
128540openSUSE Security Update : SDL_image (openSUSE-2019-2071)NessusSuSE Local Security Checks
high
127101Debian DLA-1865-1 : sdl-image1.2 security updateNessusDebian Local Security Checks
high
126927Debian DLA-1861-1 : libsdl2-image security updateNessusDebian Local Security Checks
high
124793EulerOS Virtualization 3.0.1.0 : SDL (EulerOS-SA-2019-1469)NessusHuawei Local Security Checks
high
124629EulerOS 2.0 SP3 : SDL (EulerOS-SA-2019-1343)NessusHuawei Local Security Checks
high
124267openSUSE Security Update : SDL2 (openSUSE-2019-1261)NessusSuSE Local Security Checks
high
124144openSUSE Security Update : SDL (openSUSE-2019-1223)NessusSuSE Local Security Checks
high
124106openSUSE Security Update : SDL (openSUSE-2019-1213)NessusSuSE Local Security Checks
high
124083SUSE SLED15 / SLES15 Security Update : SDL2 (SUSE-SU-2019:0950-1)NessusSuSE Local Security Checks
high
123968SUSE SLED15 / SLES15 Security Update : SDL (SUSE-SU-2019:0917-1)NessusSuSE Local Security Checks
high
123925SUSE SLED12 / SLES12 Security Update : SDL (SUSE-SU-2019:0899-1)NessusSuSE Local Security Checks
high
123625EulerOS 2.0 SP5 : SDL (EulerOS-SA-2019-1151)NessusHuawei Local Security Checks
high
123600EulerOS 2.0 SP2 : SDL (EulerOS-SA-2019-1126)NessusHuawei Local Security Checks
high
123553SUSE SLES11 Security Update : SDL (SUSE-SU-2019:13998-1)NessusSuSE Local Security Checks
high
122829Debian DLA-1714-2 : libsdl2 regression updateNessusDebian Local Security Checks
high
122828Debian DLA-1713-2 : libsdl1.2 regression updateNessusDebian Local Security Checks
high
122561Fedora 28 : SDL (2019-6092f8c0dc)NessusFedora Local Security Checks
high
122439Fedora 29 : SDL (2019-7a554204c1)NessusFedora Local Security Checks
high