icon

We found results for “

CVE-2019-12220

Good to know:

icon

Date: May 20, 2019

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an out-of-bounds read in the SDL function SDL_FreePalette_REAL at video/SDL_pixels.c.

Language: C#

Severity Score

Severity Score

Weakness Type (CWE)

Out-of-bounds Read

CWE-125

Top Fix

icon

Upgrade Version

Upgrade to version FNA.Package - 21.1.0;ppy.SDL2-CS - 1.0.75;ppy.SDL2-CS - 1.0.25;BonEngineSharp - no_fix;ImGui.SdlCs - no_fix;OpenRA-SDL2-CS - 1.0.29;Ultz.Native.SDL - 2.0.12-pre1;Ultz.Native.SDL - 2.0.14;SharpDL-SDL2-CS - 1.0.10;Xenko.Graphics - 3.1.0.1-beta01-0396+g05e746a9;Xenko.Graphics - 3.1.0.1-beta01-0318+gdb83d963;emmauss.SDL2-CS - no_fix;fnalibs - 21.1.0;SdlSharp.Redist - 0.10.6-alpha;SdlSharp - 0.12.64-alpha;Veldrid.SDL2 - 4.1.0;TwistedLogik.Ultraviolet.SDL2.Native - no_fix;Veldrid.Sdl2 - 4.0.0-beta1;serafim/ffi-sdl - 2.0.0-beta1;sdl2.nuget.redist - 2.0.14;SharpDL - 2.1.0;Stride.Graphics - 4.1.0.1728+g354f8c2e

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us